CVE-2020-36882
HIGHFlexsense DiskBoss 7.7.14 - Unauthenticated Arbitrary File Upload via Search Files Directory Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36882. PoCs published by Paras Bhatia.
AI-analyzed exploit summary This exploit generates a large buffer of 'A' characters (7000 bytes) and writes it to a file. When pasted into the 'Directory' field of DiskBoss's 'Search Files' feature, it triggers a denial of service (DoS) due to a buffer overflow vulnerability.
Description
Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.
Exploits (1)
This exploit generates a large buffer of 'A' characters (7000 bytes) and writes it to a file. When pasted into the 'Directory' field of DiskBoss's 'Search Files' feature, it triggers a denial of service (DoS) due to a buffer overflow vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H