XUpload是功能强大的客户端上传ActiveX控件,允许用户同时上传多个文件。 XUpload的ActiveX控件实现上存在缓冲区溢出漏洞,远程攻击者可能利用此漏洞控制用户系统。 XUpload的Persits.XUpload.2 ActiveX控件(XUpload.ocx)没有正确地处理传送给AddFile()方式的输入参数,如果用户受骗访问了恶意网页并向该方式传送了超长字符串参数的话,就可能触发栈溢出,导致执行任意指令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-0487 | ASPired2Protect 'login.asp' SQL注入漏洞 | |
| CVE-2008-0488 | VB Marketing 'tseekdir.cgi' 目录遍历漏洞 | |
| CVE-2008-0489 | ClanSphere 'install.php' 目录遍历漏洞 | |
| CVE-2008-0490 | WordPress Plugin WP-Cal 'functions/editevent.php' SQL注入漏洞 | |
| CVE-2008-0491 | WordPress plugin fGallery SQL注入漏洞 | |
| CVE-2008-0493 | IrfanView FlashPix插件远程堆溢出漏洞 | |
| CVE-2008-0494 | RETIRED: Endian Firewall 'userlist.php' 跨站脚本漏洞 | |
| CVE-2008-0495 | IBM Hardware Management Console Pegasus CIM Server 拒绝服务漏洞 | |
| CVE-2008-0496 | AmpJuke 'index.php' 跨站脚本攻击漏洞 | |
| CVE-2008-0497 | Nucleus CMS 'action.php' 跨站脚本攻击漏洞 | |
| CVE-2008-0498 | Bigware Shop 'main_bigware_53.tpl.php' SQL注入漏洞 | |
| CVE-2008-0499 | Mambo LaiThai SQL注入漏洞 | |
| CVE-2008-0500 | Mambo LaiThai多个未明漏洞 | |
| CVE-2008-0501 | phpMyClub 目录遍历漏洞 |
No comments yet