PT-2007-4038 · Newzcrawler · Newzcrawler
Gbr
·
Published
2007-05-16
·
Updated
2017-10-11
·
CVE-2007-2722
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
NewzCrawler version 1.8
Description
The issue allows remote attackers to cause application instability via certain invalid strings in the URL attribute of an ENCLOSURE element. This can be achieved with specific sequences such as
%s, %Y, %%, and n,.Recommendations
For NewzCrawler version 1.8, as a temporary workaround, consider restricting the use of the ENCLOSURE element or validating the input strings to prevent instability until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Newzcrawler