hi.baidu.com
http://hi.baidu.com/muma_reader/blog/item/46bd0d7a04eb75e92f73b36e.html CVE-2008-4664
Qvod Player 2.1.5 - 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow
Record summary
CVE-2008-4664 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0053 allows remote attackers to execute arbitrary code via a long URL property. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQvod Player 2.1.5 - 'QvodInsert.dll' ActiveX Control Remote Buffer OverflowExploitDB exploitby anonymousNot analyzed1 file
References
528494Third-party advisory
http://secunia.com/advisories/28494 27271vdb entry
http://www.securityfocus.com/bid/27271 qvodplayer-activex-bo(39675)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39675 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4664