vendor:
DropBox
by:
metacom
7.5
CVSS
HIGH
Heap Spray Exploit
119
CWE
Product Name: DropBox
Affected Version From: 3.1.2005
Affected Version To: 3.6.5.0
Patch Exists: YES
Related CWE: N/A
CPE: //a:etonica:dropbox
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
Unknown
Tango DropBox Activex Heap Spray Exploit
The vulnerability lies in the COM component used eSellerateControl350.dll (3.6.5.0) method of the ''GetWebStoreURL' member.
Mitigation:
Update to the latest version of the software