PT-2008-5213 · Unknown · Ultra Office Control

·

CVE-2008-3878

·

Publicado

2008-09-02

·

Atualizado

2024-02-14

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ultra Office Control version 2.0.2008.801
Description The issue is a stack-based buffer overflow in the Ultra.OfficeControl ActiveX control. This occurs when the strUrl, strFile, and strPostData parameters to the HttpUpload() method are overly long, allowing remote attackers to execute arbitrary code.
Recommendations For Ultra Office Control version 2.0.2008.801, consider disabling the HttpUpload() method until a patch is available to prevent exploitation. Restrict access to the Ultra.OfficeControl ActiveX control to minimize the risk of arbitrary code execution. Avoid using the strUrl, strFile, and strPostData parameters in the HttpUpload() method until the issue is resolved.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3878

Produtos afetados

Ultra Office Control