Html Exploits

2,076 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-4909 EXPLOITDB html VERIFIED
WinSCP < 4.0.4 - Arbitrary File Transfer via URL Scheme Interpretation Conflict
Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer commands in the final portion of a (1) scp, and possibly a (2) sftp or (3) ftp, URL, as demonstrated by a URL specifying login to the remote server with a username of scp, which is interpreted as an HTTP scheme name by the protocol handler in a web browser, but is interpreted as a username by WinSCP. NOTE: this is related to an incomplete fix for CVE-2006-3015.
by Kender.Security
CVE-2007-4814 EXPLOITDB html VERIFIED
Microsoft SQL Server - Buffer Overflow via SQLServer ActiveX Control Start Method
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
by 96sysim
EIP-2026-103855 EXPLOITDB html VERIFIED
Apple QuickTime (Multiple Browsers) - Command Execution
by pdp
CVE-2007-4890 EXPLOITDB html VERIFIED
Microsoft Visual Studio 6.0 - Arbitrary File Write via VBTOVSI.DLL SaveAs Method
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method.
by shinnai
CVE-2007-4891 EXPLOITDB html VERIFIED
Microsoft Visual Studio PDWizard.ocx - Remote Code Execution via ActiveX Control Methods
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.
by shinnai
CVE-2007-3040 EXPLOITDB html VERIFIED
Microsoft Windows 2000 - Stack-Based Buffer Overflow in Agent.Control ActiveX Control
Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
by Yamata Li
CVE-2007-4903 EXPLOITDB html VERIFIED
Ultra Crypto Component <= 2.0 - Remote Code Execution via CryptoX.dll ActiveX Buffer Overflow
Multiple buffer overflows in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allow remote attackers to execute arbitrary code via (1) a long string in the first argument to the AcquireContext method or (2) an unspecified vector to the DeleteContext method.
by shinnai
CVE-2007-4902 EXPLOITDB html VERIFIED
Ultra Crypto Component <= 2.0 - Arbitrary File Write via CryptoX.dll SaveToFile Method
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Component allows remote attackers to write to arbitrary files via a full pathname in the argument to the SaveToFile method.
by shinnai
CVE-2007-4814 EXPLOITDB html VERIFIED
Microsoft SQL Server - Buffer Overflow via SQLServer ActiveX Control Start Method
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQL Server Enterprise Manager 8.05.2004 allows remote attackers to execute arbitrary code via a long second argument to the Start method.
by rgod
CVE-2007-4805 EXPLOITDB html VERIFIED
fuzzylime (cms) <= 3.0 - Path Traversal via getgalldata.php p Parameter
Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) in the p parameter.
by not sec group
CVE-2007-4802 EXPLOITDB html VERIFIED
GlobalLink 2.7.0.8 - Remote Code Execution via glItemCom.dll or glitemflat.dll ActiveX Control
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.
by void
CVE-2007-4821 EXPLOITDB html VERIFIED
EDraw Office Viewer Component 5.2 - Remote Code Execution via HttpDownloadFileToTempDir Method
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows remote attackers to execute arbitrary code via a long first argument to the HttpDownloadFileToTempDir method, a different vulnerability than CVE-2007-3169.
by shinnai
CVE-2007-4790 EXPLOITDB html VERIFIED
Internet Explorer - Stack-Based Buffer Overflow via FoxDoCmd Function
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function.
by shinnai
CVE-2007-4802 EXPLOITDB html VERIFIED
GlobalLink 2.7.0.8 - Remote Code Execution via glItemCom.dll or glitemflat.dll ActiveX Control
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.
by void
CVE-2007-4722 EXPLOITDB html VERIFIED
Move Media Player - Stack-Based Buffer Overflow via Play or Buzzer Method
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods.
by anonymous
CVE-2007-4740 EXPLOITDB html VERIFIED
Telecom Italy Alice Messenger - Unauthenticated Registry Manipulation via HPRevolutionRegistryManager ActiveX Control
The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to create registry keys and values via the arguments to the WriteRegistry method.
by rgod
CVE-2007-4718 EXPLOITDB html VERIFIED
Claroline < 1.8.6 - Remote File Inclusion via Language Parameter
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
by Fernando Munoz
CVE-2007-4515 EXPLOITDB html VERIFIED
Yahoo! services suite - Buffer Overflow
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are obtained from third party information.
by minhbq
CVE-2007-4607 EXPLOITDB html VERIFIED
Quiksoft EasyMail SMTP Object <6.0.1 - Buffer Overflow
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15.
by rgod
CVE-2007-4582 EXPLOITDB html VERIFIED
ACTi Network Video Recorder SP2 2.0 - Remote Code Execution via nvUnifiedControl.AUnifiedControl.1 SetText Method
Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allows remote attackers to execute arbitrary code via a long second argument to the SetText method.
by shinnai
CVE-2007-4583 EXPLOITDB html VERIFIED
ACTi Network Video Recorder SP2 2.0 - Path Traversal and Arbitrary File Write via nvUtility.Utility.1 ActiveX Control
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method.
by shinnai
CVE-2007-4583 EXPLOITDB html VERIFIED
ACTi Network Video Recorder SP2 2.0 - Path Traversal and Arbitrary File Write via nvUtility.Utility.1 ActiveX Control
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method.
by shinnai
CVE-2007-4489 EXPLOITDB html VERIFIED
eCentrex VOIP Client <2.0.1 - Buffer Overflow
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote attackers to execute arbitrary code via a long Username argument to the ReInit method.
by rgod
CVE-2007-4420 EXPLOITDB html VERIFIED
EDraw Office Viewer Component 5.1 - Path Traversal
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the HttpDownloadFile method, a different vulnerability than CVE-2007-3168 and CVE-2007-3169.
by shinnai
CVE-2007-1749 EXPLOITDB html VERIFIED
Internet Explorer 5.01, 6, and 7 - Remote Code Execution via VML Integer Underflow
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.
by Ben Nagy & Derek Soeder