Hummingbird · Hummingbird Xweb Activex Control · CVE-2008-4729
**Name of the Vulnerable Software and Affected Versions**
Hummingbird Xweb ActiveX Control versions 13.0 and earlier
**Description**
The issue is related to a stack-based buffer overflow in the Hummingbird.XWebHostCtrl.1 ActiveX control, specifically in the hclxweb.dll file. This occurs when a long `PlainTextPassword` property is provided, potentially allowing remote attackers to execute arbitrary code. It is noted that code execution might not be possible in version 13.0.
**Recommendations**
For Hummingbird Xweb ActiveX Control versions 13.0 and earlier, consider disabling the `PlainTextPassword` property as a temporary workaround until a patch is available. Restrict access to the hclxweb.dll file to minimize the risk of exploitation.