9.3
CVSSv2

CVE-2008-0660

Published: 08/02/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote malicious users to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.

Vulnerable Product Search on Vulmon Subscribe to Product

facebook photouploader 4.5.57.0

aurigma image uploader activex control 4.6.17.0

aurigma image uploader activex control 5.0.10.0

facebook facebook

aurigma image uploader activex control 4.5.126.0

aurigma image uploader activex control 4.5.70.0

Exploits

<!-- FaceBook PhotoUploader Buffer Overflow Exploit written by eb Tested on Windows XP SP2(fully patched) English, IE6, ImageUploader4ocx 45570(FaceBookPhotoUploader2cab) The following controls are also vulnerable: Aurigma ImageUploader4 45700 and 451260 ----------------------------- {6E5E167B-1566-4316-B27F-0DDAB3484CF7} Buffer ...