6.8
CVSSv2

CVE-2008-4048

Published: 11/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote malicious users to execute arbitrary code via a long third argument to the CreateURLShortcut method.

Vulnerable Product Search on Vulmon Subscribe to Product

friendly technologies friendly pppoe client 3.0.0.57

Exploits

<!-- "Friendly Technologies" provide software like L2TP and PPPoE clients to ISPs, who give the software to their customers on CD so they have less trouble setting up thire connections They also provide remote configuration solutions not the best idea if you ask me An overflow exists in fwRemoteCfgdll provided with the dialer, an example ...