45886vdb entry
http://osvdb.org/45886 CVE-2007-4802
GlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap Overflow
Record summary
CVE-2007-4802 has a selected CVSS score of 6.8; EIP currently links 2 catalogued exploits.
Description
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a long eighth argument to the SetInfo method in a certain ActiveX control in glItemCom.dll or (2) a long second argument to the SetClientInfo method in a certain ActiveX control in glitemflat.dll.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBGlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap OverflowExploitDB exploitby voidNot analyzed1 file
ExploitDBGlobalLink 2.7.0.8 - 'glitemflat.dll SetClientInfo()' Heap OverflowExploitDB exploitby voidNot analyzed1 file
References
945887vdb entry
http://osvdb.org/45887 25565vdb entry
http://www.securityfocus.com/bid/25565 25586vdb entry
http://www.securityfocus.com/bid/25586 globallink-glitemcom-bo(36470)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/36470 globallink-glitemflat-bo(36501)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/36501 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4802 4366exploit
https://www.exploit-db.com/exploits/4366 4372exploit
https://www.exploit-db.com/exploits/4372