DigitalVolcano TextCrawler Pro Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in DigitalVolcano TextCrawler Pro version 3.1.1. This issue allows attackers to crash the application by sending an oversized buffer in the license key field. Exploitation involves generating a 6000-byte payload and pasting it into the activation field, which triggers the application to crash.
Impact
Exploitation of this vulnerability leads to a crash of the TextCrawler Pro application, causing a denial-of-service condition.
Reproduction
To reproduce this vulnerability, create a 6000-byte payload consisting of repeated characters. Save this payload in a text file. Open TextCrawler Pro version 3.1.1 on a Windows 7 x64 system. Copy the contents of the text file into the 'License key' field. Click 'Activate', and the application will crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
