Vulnerabilities > CVE-2007-3071 - Unspecified vulnerability in Digital River Esellerate SDK 3.6.5.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN digital-river
exploit available
Summary
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Tango DropBox 3.1.5 + PRO - Activex Heap Spray. CVE-2007-3071. Webapps exploit for windows platform id EDB-ID:37319 last seen 2016-02-04 modified 2015-06-19 published 2015-06-19 reporter metacom source https://www.exploit-db.com/download/37319/ title Tango DropBox 3.1.5 + PRO - Activex Heap Spray description eSellerate SDK 3.6.5 eSellerateControl365.DLL ActiveX Control Buffer Overflow Vulnerability. CVE-2007-3071 . Remote exploit for windows platform id EDB-ID:30144 last seen 2016-02-03 modified 2007-06-04 published 2007-06-04 reporter shinnai source https://www.exploit-db.com/download/30144/ title eSellerate SDK 3.6.5 eSellerateControl365.DLL ActiveX Control Buffer Overflow Vulnerability
References
- http://osvdb.org/38803
- http://osvdb.org/38803
- http://www.securityfocus.com/bid/24300
- http://www.securityfocus.com/bid/24300
- http://www.shinnai.altervista.org/exploits/esellerate.html
- http://www.shinnai.altervista.org/exploits/esellerate.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35003
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35003