vendor:
SAP KWEdit ActiveX Control
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: SAP KWEdit ActiveX Control
Affected Version From: 6400.1.1.41
Affected Version To: 6400.1.1.41
Patch Exists: NO
Related CWE: CVE-2007-3605, OSVDB-37690, BID-24772
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Pro SP0/SP1 English, Windows 2000 Pro English All
2007
EnjoySAP SAP GUI ActiveX Control Buffer Overflow
This module exploits a stack buffer overflow in SAP KWEdit ActiveX Control (kwedit.dll 6400.1.1.41) provided by EnjoySAP GUI. By sending an overly long string to the "PrepareToPostHTML()" method, an attacker may be able to execute arbitrary code.
Mitigation:
No known mitigation or remediation for this vulnerability