PT-2009-4057 · Lateral Arts · Lateral Arts Photobox Uploader Activex Control

Publicado

2009-12-03

·

Atualizado

2018-10-10

·

CVE-2009-1567

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Lateral Arts Photobox uploader ActiveX control versions 1.x through 1.2 Lateral Arts Photobox uploader ActiveX control version 2.2.0.6
Description: The issue is related to multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control. Remote attackers can execute arbitrary code via a long URL string for certain property values, including LogURL, ConnectURL, SkinURL, AlbumCreateURL, ErrorURL, or httpsinglehost.
Recommendations: For Lateral Arts Photobox uploader ActiveX control versions 1.x through 1.2, update to version 1.3 or later. For Lateral Arts Photobox uploader ActiveX control version 2.2.0.6, consider disabling the ActiveX control until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-1567

Produtos afetados

Lateral Arts Photobox Uploader Activex Control