9.3
CVSSv2

CVE-2010-2590

Published: 22/12/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote malicious users to execute arbitrary code via a long ServerResourceVersion property value.

Vulnerable Product Search on Vulmon Subscribe to Product

sap crystal reports 2008

Exploits

## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = NormalRanking inc ...
<!-- Crystal Reports Viewer 1200549 Activex Exploit (PrintControldll) 0-day By = Dr_IDE File = "C:\Program Files\BusinessObjects\Common\40\crystalreportviewers12\ActiveXControls\PrintControldll" method = "ServerResourceVersion" progid = "CrystalPrintControlLibCrystalPrintControl" Site = wwwsapcom Tested On = Windows XPSP3 VM with ...