9.3
CVSSv2

CVE-2007-6530

Published: 27/12/2007 Updated: 08/03/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions prior to 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote malicious users to execute arbitrary code via a long argument to the AddFolder function.

Vulnerable Product Search on Vulmon Subscribe to Product

persits xupload 2.1.0.1

groove virtual office

hp loadrunner

Exploits

<!-- written by eb Persits Software XUpload Control AddFolder() Buffer Overflow Exploit Tested on Windows XP SP2(fully patched) English, IE6 and IE7 Thanks to hdm and the Metasploit crew --> <html> <head> <title>Persits Software XUpload Control AddFolder BoF Exploit</title> <script language="JavaScrip ...
## # $Id: hp_loadrunner_addfolderrb 9262 2010-05-09 17:45:00Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...