10
CVSSv2

CVE-2008-0437

Published: 23/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote malicious users to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

hp virtual rooms 1.0.0.100

microsoft activex

Exploits

<!-- HP Virtual Rooms WebHPVCInstall Control Buffer Overflow Exploit written by eb Note that I did not have time to work out some heap fragmentation issues so this code is NOT reliable Tested on Windows XP SP2(fully patched) English, IE6, hpvirtualrooms14dll version 100100 Thanks to rgod, hdm and the Metasploit crew --> <html ...