Html Exploits

2,076 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-3983 EXPLOITDB html VERIFIED
ActiveReports 2.5.0.1308 - Arbitrary File Write via SaveLayout Method
Absolute path traversal vulnerability in the Data Dynamics DDActiveReports2.ActiveReport.2 (ActiveReports) ActiveX control in arpro2.dll in ActiveReports 2.0 Professional Edition 2.5.0.1308 (SP5 RC) allows remote attackers to create or overwrite arbitrary files via a full pathname in an argument to the SaveLayout method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by shinnai
CVE-2007-4919 EXPLOITDB html VERIFIED
JBlog 1.0 - SQL Injection via id Parameter
Multiple SQL injection vulnerabilities in JBlog 1.0 allow (1) remote attackers to execute arbitrary SQL commands via the id parameter to index.php, and allow (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter to admin/modifpost.php.
by s4mi
CVE-2007-2563 EXPLOITDB html VERIFIED
VersalSoft HTTP File Upload < - RCE
Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument.
by shinnai
CVE-2007-3939 EXPLOITDB html VERIFIED
SpoonLabs Vivvo Article Management CMS < 3.40 - SQL Injection via Category Parameter
SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
by ajann
CVE-2007-3883 EXPLOITDB html VERIFIED
Data Dynamics ActiveBar <3.2 - Path Traversal
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in (1) the second argument to the Save method, or the first argument to the (2) SaveLayoutChanges or (3) SaveMenuUsageData method.
by shinnai
CVE-2007-3785 EXPLOITDB html VERIFIED
EldoS SecureBlackbox 5.1.0.112 - Absolute Path Traversal via SaveToFile Method
Absolute path traversal vulnerability in a certain ActiveX control in PGPBBox.dll in EldoS SecureBlackbox (sbb) 5.1.0.112 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by callAX
EIP-2026-119053 EXPLOITDB html VERIFIED
Program Checker - 'sasatl.dll 1.5.0.531' DebugMsgLog HeapSpray
by callAX
CVE-2007-3703 EXPLOITDB html VERIFIED
Zenturi Program Checker Pro - Stack-Based Buffer Overflow via Fill Method
Stack-based buffer overflow in a certain ActiveX control in sasatl.dll 1.5.0.531 in Zenturi Program Checker (ProgramChecker) Pro allows remote attackers to execute arbitrary code via a long argument to the Fill method. NOTE: this is probably a different issue than CVE-2007-2987.
by callAX
CVE-2006-6707 EXPLOITDB html VERIFIED
McAfee NeoTrace and Visual Trace 3.25 - Stack-Based Buffer Overflow via TraceTarget Method
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
by nitr0us
CVE-2007-3633 EXPLOITDB html VERIFIED
Chilkat Zip ActiveX Control - Absolute Path Traversal via SaveLastError Method
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.
by shinnai
CVE-2007-3649 EXPLOITDB html VERIFIED
HP Photo Digital Imaging ActiveX Control - Arbitrary File Write via SaveToFile Method
Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method.
by shinnai
CVE-2007-3607 EXPLOITDB html VERIFIED
EnjoySAP - Denial of Service via ActiveX Control
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.
by Mark Litchfield
CVE-2007-3607 EXPLOITDB html VERIFIED
EnjoySAP - Denial of Service via ActiveX Control
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denial of service (process crash) via unspecified vectors.
by Mark Litchfield
CVE-2007-3606 EXPLOITDB html VERIFIED
SAP EnjoySAP - Heap-Based Buffer Overflow via LaunchGui Function
Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function.
by Mark Litchfield
CVE-2007-3605 EXPLOITDB html VERIFIED
EnjoySAP SAP GUI - Stack-Based Buffer Overflow via PrepareToPostHTML Function
Stack-based buffer overflow in the kweditcontrol.kwedit.1 ActiveX control in FrontEnd\SapGui\kwedit.dll in the EnjoySAP SAP GUI allows remote attackers to execute arbitrary code via a long argument to the PrepareToPostHTML function.
by Mark Litchfield
CVE-2007-3608 EXPLOITDB html VERIFIED
EnjoySAP SAP GUI - Unspecified Vuln
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors.
by Mark Litchfield
CVE-2007-3608 EXPLOITDB html VERIFIED
EnjoySAP SAP GUI - Unspecified Vuln
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certain files via unspecified vectors.
by Mark Litchfield
CVE-2007-2239 EXPLOITDB html VERIFIED
AXIS Network Cameras < 2.39 - Stack-Based Buffer Overflow via SaveBMP Method
Stack-based buffer overflow in the SaveBMP method in the AXIS Camera Control (aka CamImage) ActiveX control before 2.40.0.0 in AxisCamControl.ocx in AXIS 2100, 2110, 2120, 2130 PTZ, 2420, 2420-IR, 2400, 2400+, 2401, 2401+, 2411, and Panorama PTZ allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long argument.
by shinnai
CVE-2007-3554 EXPLOITDB html VERIFIED
HP Instant Support - Driver Check < 1.5.0.3 - Remote Code Execution via HPSDDX ActiveX queryHub Function
Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote attackers to execute arbitrary code via a long argument to the queryHub function.
by shinnai
CVE-2007-3536 EXPLOITDB html VERIFIED
AMX NetLinx VNC ActiveX Control - Buffer Overflow via Long Host, Password, or LogFile Property Values
Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values.
by rgod
CVE-2007-3487 EXPLOITDB html VERIFIED
HP Photo Digital Imaging ActiveX Control - Arbitrary File Write via saveXMLAsFile Method
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.
by callAX
CVE-2007-3488 EXPLOITDB html VERIFIED
Sony Network Camera SNC-P5 < 1.29 - Remote Code Execution via PrmSetNetworkParam Method
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N, SNC-DF80N, and SNC-DF50N before 1.12; and SNC-RX570N/W, SNC-RX570N/B, SNC-RX550N/W, SNC-RX550N/B, SNC-RX530N/W, and SNC-RX530N/B 3.00 and 2.x before 2.31; allows remote attackers to execute arbitrary code via a long first argument to the PrmSetNetworkParam method.
by str0ke
CVE-2007-3410 EXPLOITDB html VERIFIED
RealNetworks Helix Player and RealPlayer - Stack-Based Buffer Overflow via SMIL Wallclock Value
Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2) file with a long wallclock value.
by axis
CVE-2007-3493 EXPLOITDB html VERIFIED
NCTAudioStudio <2.7 - Path Traversal
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the CreateFile method, a different product than CVE-2007-3400.
by shinnai
CVE-2007-3459 EXPLOITDB html VERIFIED
Avaxswf.dll 1.0.0.1 - Path Traversal
A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the WriteMovie method.
by callAX