CVE-2021-47765
MEDIUMAbsoluteTelnet 11.24 - Denial of Service via Username or Email Field Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47765. PoCs published by Yehia Elghaly.
AI-analyzed exploit summary This PoC exploits a denial-of-service vulnerability in AbsoluteTelnet 11.24 by overflowing the 'Username' field with a large number of 'A' characters, causing the application to crash. The exploit generates a text file containing the payload, which is then manually input into the application.
Description
AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can trigger the crash by inserting 1000 characters into the username or email address fields, causing the application to become unresponsive.
Exploits (1)
This PoC exploits a denial-of-service vulnerability in AbsoluteTelnet 11.24 by overflowing the 'Username' field with a large number of 'A' characters, causing the application to crash. The exploit generates a text file containing the payload, which is then manually input into the application.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H