CVE-2011-3142
high · 10Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote attackers to execute arbitrary code via a long second argument to the ValidateUser method.
10
CVSS
38.1%
EPSS (exploit prob.)
98th
EPSS percentile
2011-08-16
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wellintech | kingview | 6.52 |
| wellintech | kingview | 6.53 |
Check a specific version with /api/v1/cve/match.
References
- http://www.cnvd.org.cn/vulnerability/CNVD-2011-04541
- http://www.exploit-db.com/exploits/16936
- http://www.kingview.com/news/detail.aspx?contentid=537
- http://www.osvdb.org/72889
- http://www.scadahacker.com/exploits-wellintech-kvwebsvr.html
- http://www.securityfocus.com/bid/46757
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-066-01.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-074-01.pdf
- http://www.cnvd.org.cn/vulnerability/CNVD-2011-04541
- http://www.exploit-db.com/exploits/16936
- http://www.kingview.com/news/detail.aspx?contentid=537
- http://www.osvdb.org/72889
- http://www.scadahacker.com/exploits-wellintech-kvwebsvr.html
- http://www.securityfocus.com/bid/46757
- http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-066-01.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-11-074-01.pdf
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-3142