CVE-2020-37130
HIGHNsauditor < 3.2.0.0 - Denial of Service via Registration Name Input Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37130. PoCs published by 0xMoHassan.
AI-analyzed exploit summary This Python script generates a 1000-byte buffer of 'A' characters to trigger a Denial of Service (DoS) in Nsauditor 3.2.0.0 by overflowing the 'Name' field during registration. The exploit is local and requires user interaction to paste the payload.
Description
Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field.
Exploits (1)
This Python script generates a 1000-byte buffer of 'A' characters to trigger a Denial of Service (DoS) in Nsauditor 3.2.0.0 by overflowing the 'Name' field during registration. The exploit is local and requires user interaction to paste the payload.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H