Back to CVE List

CVE-2018-25294

HIGH SEVERITY

CVSS Score & Metrics

Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
Cewe-Photoworld
Product
CEWE Photoshow

External References

Discussion (0)

Add Comment

No comments yet. Be the first!