CVE-2007-6530
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 37%
from disclosure to weapon1 days
Published on NVDDec 27
1st PoC+1d
metasploitDec 25
exploitation probability
37%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16588unverifiedexploitdbwww.exploit-db.com/exploits/4806unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=full-disclosure&m=119863639428564&w=2http://osvdb.org/39901http://secunia.com/advisories/28145http://secunia.com/advisories/28205http://secunia.com/advisories/28218http://www.securityfocus.com/bid/27025http://www.securitytracker.com/id?1019147http://www.vupen.com/english/advisories/2007/4310