CVE-2008-3480

Anzio WePO <3.2.19-3.2.24 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3480. PoCs published by Core Security.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow in the Anzio Web Print Object ActiveX component via a long 'mainurl' parameter, allowing arbitrary code execution through SEH overwrite and heap spraying. The PoC generates an HTML file that triggers the vulnerability to launch the Windows Calculator.

Description

Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Print Wizard, allows remote attackers to execute arbitrary code via a long mainurl parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Core Security · textremotewindows
https://www.exploit-db.com/exploits/6278

This exploit demonstrates a buffer overflow in the Anzio Web Print Object ActiveX component via a long 'mainurl' parameter, allowing arbitrary code execution through SEH overwrite and heap spraying. The PoC generates an HTML file that triggers the vulnerability to launch the Windows Calculator.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Anzio Web Print Object 3.2.19, 3.2.24
No auth needed
Prerequisites: Victim must have vulnerable Anzio Web Print Object installed · Victim must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2417
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31554
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30545
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4197
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6278
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/495630/100/0/threaded

Scores

EPSS 0.1116
EPSS Percentile 95.4%

Details

CWE
CWE-119
Status published
Products (3)
anzio/print_wizard 3.2.19 (2 CPE variants)
anzio/web_print_object 3.2.19
anzio/web_print_object 3.2.24
Published Aug 29, 2008
Tracked Since Feb 18, 2026