CVE-2008-0660

Aurigma Image Uploader ActiveX Control Stack-Based Buffer Overflow via ExtractExif/ExtractIptc

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0660. PoCs published by Elazar.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the Aurigma ImageUploader ActiveX control (CVE-2008-5711). It uses a crafted HTML page with JavaScript to trigger the overflow, leveraging SEH overwrites and shellcode to achieve remote code execution.

Description

Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Elazar · htmlremotewindows
https://www.exploit-db.com/exploits/5049

This exploit targets a buffer overflow vulnerability in the Aurigma ImageUploader ActiveX control (CVE-2008-5711). It uses a crafted HTML page with JavaScript to trigger the overflow, leveraging SEH overwrites and shellcode to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Aurigma ImageUploader4/5 (versions 4.5.57.0, 4.5.70.0, 4.5.126.0, 4.6.17.0, 5.0.10.0)
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer with the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2008/Feb/0023.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0394/references
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27576
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28707
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0391/references
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28713
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5049
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27577
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019297
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/776931

Scores

EPSS 0.3776
EPSS Percentile 98.4%

Details

CWE
CWE-119
Status published
Products (6)
aurigma/image_uploader_activex_control 4.5.70.0
aurigma/image_uploader_activex_control 4.5.126.0
aurigma/image_uploader_activex_control 4.6.17.0
aurigma/image_uploader_activex_control 5.0.10.0
facebook/facebook
facebook/photouploader 4.5.57.0
Published Feb 08, 2008
Tracked Since Feb 18, 2026