A buffer overflow exists in XUpload. XUpload.ocx fails to validate string data passed to the AddFolder() method resulting in a stack overflow. With a specially crafted web site, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity.
Classification
Location:
Local / Remote
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Upgrade
Exploit:
Exploit Available
Disclosure:
Uncoordinated Disclosure
OSVDB:
Context Dependent
Technical
The vulnerability does not affect Office Groove 2007.
Solution
Upgrade to version 3.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.