vendor:
ImageUploader4
by:
e.b.
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ImageUploader4
Affected Version From: 4.5.57.0
Affected Version To: 5.0.10.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:aurigma:imageuploader4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2008
FaceBook PhotoUploader Buffer Overflow Exploit
A buffer overflow vulnerability exists in Facebook PhotoUploader, which is an ActiveX control used by Facebook to upload photos. The vulnerability is caused due to a boundary error when handling a specially crafted HTML page. This can be exploited to cause a stack-based buffer overflow via an overly long, specially crafted argument passed to the vulnerable ActiveX control. Successful exploitation may allow execution of arbitrary code.
Mitigation:
Upgrade to the latest version of Facebook PhotoUploader.