CVE-2007-4474
CVE-2007-4474
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
Productos afectados
n/a · n/aPoCs públicas encontradas — 4
cve_referencewww.exploit-db.com/exploits/4818no verificadocve_referencewww.exploit-db.com/exploits/4820no verificadocve_referencewww.exploit-db.com/exploits/5111no verificadoexploitdbwww.exploit-db.com/exploits/16502no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.grok.org.uk/pipermail/full-disclosure/2007-December/059233.htmlhttp://osvdb.org/40954http://secunia.com/advisories/28184https://exchange.xforce.ibmcloud.com/vulnerabilities/39175https://www.exploit-db.com/exploits/4818https://www.exploit-db.com/exploits/4820https://www.exploit-db.com/exploits/5111http://www.kb.cert.org/vuls/id/963889http://www.securityfocus.com/bid/26972http://www.securitytracker.com/id?1019138http://www.vupen.com/english/advisories/2007/4296