Vulnerabilities > CVE-2007-3606 - ActiveX Controls Multiple Unspecified vulnerability in EnjoySAP

047910
CVSS 7.6 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
high complexity
sap
exploit available

Summary

Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCII versions, allows remote attackers to execute arbitrary code via a long first argument to the LaunchGui function.

Vulnerable Configurations

Part Description Count
Application
Sap
1

Exploit-Db

descriptionEnjoySAP ActiveX rfcguisink.rfcguisink.1 Remote Heap Overflow PoC. CVE-2007-3606,CVE-2007-3607,CVE-2007-3608. Dos exploit for windows platform
fileexploits/windows/dos/4149.html
idEDB-ID:4149
last seen2016-01-31
modified2007-07-05
platformwindows
port
published2007-07-05
reporterMark Litchfield
sourcehttps://www.exploit-db.com/download/4149/
titleEnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow PoC
typedos