9.3
CVSSv2

CVE-2010-4321

Published: 30/12/2010 Updated: 21/09/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote malicious users to execute arbitrary code via a long argument to (1) the GetDriverSettings2 method, as reachable by (2) the GetDriverSettings method.

Vulnerable Product Search on Vulmon Subscribe to Product

novell iprint client 5.52

Exploits

## # $Id: novelliprint_getdriversettings_2rb 11888 2011-03-07 02:28:15Z bannedit $ ## ### # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## requ ...
<!-- Novell iPrint <= 552 ActiveX GetDriverSettings() Remote Exploit (ZDI-10-256) Coded By: Dr_IDE Reference: wwwzerodayinitiativecom/advisories/ZDI-10-256/ Reference: wwwvupencom/english/advisories/2010/3023 Tested On: Windows XP SP3 --> <html> <object classid='clsid:36723F97-7AA0-11D4-8919-FF2D71D0D32C' id='ta ...