CVE-2018-25294
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Description
CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
Cewe-Photoworld
Product
CEWE Photoshow
Discussion (0)
Add Comment
No comments yet. Be the first!