vendor:
XUpload
by:
jduck
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: XUpload
Affected Version From: 3.0.0.3
Affected Version To: 3.0.0.3
Patch Exists: NO
Related CWE: CVE-2008-0492, OSVDB-40762, BID-27456
CPE: a:persits_software:xupload
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 / IE6 SP3
2007
Persits XUpload ActiveX AddFile Buffer Overflow
This module exploits a stack buffer overflow in Persits Software Inc's XUpload ActiveX control(version 3.0.0.3) thats included in HP LoadRunner 9.5. By passing an overly long string to the AddFile method, an attacker may be able to execute arbitrary code.
Mitigation:
No known mitigation or remediation for this vulnerability