CVE-2007-6530
high · 9.3Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.
9.3
CVSS
36.8%
EPSS (exploit prob.)
98th
EPSS percentile
2007-12-27
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| groove | virtual_office | all versions |
| hp | loadrunner | all versions |
| persits | xupload | 2.1.0.1 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=full-disclosure&m=119863639428564&w=2
- http://osvdb.org/39901
- http://secunia.com/advisories/28145
- http://secunia.com/advisories/28205
- http://secunia.com/advisories/28218
- http://www.securityfocus.com/bid/27025
- http://www.securitytracker.com/id?1019147
- http://www.vupen.com/english/advisories/2007/4310
- http://marc.info/?l=full-disclosure&m=119863639428564&w=2
- http://osvdb.org/39901
- http://secunia.com/advisories/28145
- http://secunia.com/advisories/28205
- http://secunia.com/advisories/28218
- http://www.securityfocus.com/bid/27025
- http://www.securitytracker.com/id?1019147
- http://www.vupen.com/english/advisories/2007/4310
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-6530