CVE-2007-6530

Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:groove:virtual_office:*:*:*:*:*:*:*:*
cpe:2.3:a:hp:loadrunner:*:*:*:*:*:*:*:*
cpe:2.3:a:persits:xupload:2.1.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:40

Type Values Removed Values Added
References () http://marc.info/?l=full-disclosure&m=119863639428564&w=2 - Exploit () http://marc.info/?l=full-disclosure&m=119863639428564&w=2 - Exploit
References () http://osvdb.org/39901 - () http://osvdb.org/39901 -
References () http://secunia.com/advisories/28145 - Vendor Advisory () http://secunia.com/advisories/28145 - Vendor Advisory
References () http://secunia.com/advisories/28205 - Vendor Advisory () http://secunia.com/advisories/28205 - Vendor Advisory
References () http://secunia.com/advisories/28218 - Vendor Advisory () http://secunia.com/advisories/28218 - Vendor Advisory
References () http://www.securityfocus.com/bid/27025 - Exploit () http://www.securityfocus.com/bid/27025 - Exploit
References () http://www.securitytracker.com/id?1019147 - () http://www.securitytracker.com/id?1019147 -
References () http://www.vupen.com/english/advisories/2007/4310 - () http://www.vupen.com/english/advisories/2007/4310 -

Information

Published : 2007-12-27 22:46

Updated : 2024-11-21 00:40


NVD link : CVE-2007-6530

Mitre link : CVE-2007-6530

CVE.ORG link : CVE-2007-6530


JSON object : View

Products Affected

hp

  • loadrunner

persits

  • xupload

groove

  • virtual_office
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer