9.3
CVSSv2

CVE-2008-1724

Published: 11/04/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in Tumbleweed SecureTransport Server prior to 4.6.1 Hotfix 20 allows remote malicious users to execute arbitrary code via a long remoteFile parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tumbleweed securetransport_server_app

Exploits

## # $Id: tumbleweed_filetransferrb 9525 2010-06-15 07:18:08Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...
<!-- aushackcom - Vulnerability Advisory ----------------------------------------------- Release Date: 07-Apr-2008 Software: Tumbleweed Communications - SecureTransport FileTransfer wwwtumbleweedcom/ Description: "Tumbleweed SecureTransport is the industry's most secure Managed File Transfer solution for moving financial transa ...