CVE-2019-25592
MEDIUMPHPRunner 10.1 Denial of Service via Dashboard Name Field
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25592. PoCs published by Victor Mondragón.
AI-analyzed exploit summary This exploit demonstrates a Denial of Service (DoS) vulnerability in PHPRunner 10.1 by creating a large string of 'A' characters (10,000 bytes) and writing it to a file. When this content is pasted into the 'Name' field during dashboard creation, it triggers a crash.
Description
PHPRunner 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the dashboard name field. Attackers can paste a buffer of 10000 characters into the Name field during dashboard creation to trigger an application crash.
Exploits (1)
This exploit demonstrates a Denial of Service (DoS) vulnerability in PHPRunner 10.1 by creating a large string of 'A' characters (10,000 bytes) and writing it to a file. When this content is pasted into the 'Name' field during dashboard creation, it triggers a crash.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H