CVE-2007-6530 Information

Description

Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1 and probably other versions before 3.0 as used by HP Mercury LoadRunner and Groove Virtual Office allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.

Reference

http://marc.info/?l=full-disclosure&m=119863639428564&w=2 http://osvdb.org/39901 http://secunia.com/advisories/28145 http://secunia.com/advisories/28205 http://secunia.com/advisories/28218 http://www.securityfocus.com/bid/27025 http://www.securitytracker.com/id?1019147 http://www.vupen.com/english/advisories/2007/4310

Share on: