CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
98.0%
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.
Vendor | Product | Version | CPE |
---|---|---|---|
aurigma | image_uploader_activex_control | * | cpe:2.3:a:aurigma:image_uploader_activex_control:*:*:*:*:*:*:*:* |
myspace | myspaceuploader | 1.0.0.4 | cpe:2.3:a:myspace:myspaceuploader:1.0.0.4:*:*:*:*:*:*:* |
blogs.aurigma.com/post/2008/01/Another-security-problem---oh%2c-not-again.aspx
seclists.org/fulldisclosure/2008/Jan/0593.html
secunia.com/advisories/28715
secunia.com/advisories/28733
www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9060483
www.kb.cert.org/vuls/id/776931
www.securityfocus.com/bid/27533
www.vupen.com/english/advisories/2008/0344/references
www.vupen.com/english/advisories/2008/0345/references
exchange.xforce.ibmcloud.com/vulnerabilities/40118
www.exploit-db.com/exploits/5025