10
CVSSv2

CVE-2008-0659

Published: 08/02/2008 Updated: 29/09/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and previous versions, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote malicious users to execute arbitrary code via a long Action property.

Vulnerable Product Search on Vulmon Subscribe to Product

myspace myspaceuploader 1.0.0.4

aurigma image uploader activex control

Exploits

<!-- MySpace Uploader Buffer Overflow Exploit written by eb Tested on Windows XP SP2(fully patched) English, IE6 MySpaceUploaderocx version 1004: {48DD0448-9209-4F81-9F6D-D83562940134} Aurigma ImageUploader4ocx version version 45700: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} Thanks to hdm and the Metasploit crew --> <html> ...