SpotMSN Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in SpotMSN version 2.4.6. The issue arises in the registration name input field, where attackers can crash the application by entering a 1000-character payload. This payload can be generated and saved into a text file, which is then copied and pasted into the 'Name' field during the registration process.
Impact
Exploitation of this vulnerability leads to a crash of the SpotMSN application, causing a denial-of-service condition.
Reproduction
To reproduce this vulnerability, download and install SpotMSN version 2.4.6. After installation, run a Python script that creates a file containing a 1000-character payload. Open the SpotMSN application and navigate to the registration section. Copy the payload from the file and paste it into the 'Name' field. Click 'Ok' to complete the registration. The application will crash, demonstrating the denial-of-service vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
