CVE-2020-36994
MEDIUMQlikView 12.50.20000.0 - Denial of Service via FTP Server Address Input Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36994. PoCs published by Luis Martínez.
AI-analyzed exploit summary This PoC exploits a local Denial of Service (DoS) vulnerability in QlikView 12.50.20000.0 by overflowing the 'FTP Server Address' field with a buffer of 300 'A' characters, causing the application to crash when pasted and connected.
Description
QlikView 12.50.20000.0 contains a denial of service vulnerability in the FTP server address input field that allows local attackers to crash the application. Attackers can paste a 300-character buffer into the FTP server address field to trigger an application crash and prevent normal functionality.
Exploits (1)
This PoC exploits a local Denial of Service (DoS) vulnerability in QlikView 12.50.20000.0 by overflowing the 'FTP Server Address' field with a buffer of 300 'A' characters, causing the application to crash when pasted and connected.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H