CVE-2008-3878
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 36%
from disclosure to weapon748 days
Published on NVDSep 2
1st PoC+748d
metasploitAug 27
exploitation probability
36%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/6318unverifiedexploitdbwww.exploit-db.com/exploits/16513unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/31632http://securityreason.com/securityalert/4200https://exchange.xforce.ibmcloud.com/vulnerabilities/44749https://www.exploit-db.com/exploits/6318http://www.securityfocus.com/bid/30861http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219826651.ff.phphttp://www.shinnai.net/xplits/TXT_RvfuIrwypWLMaiVn33Iy.html