eBay Enhanced Picture Services ActiveX Control Unspecified Remote Code Execution Vulnerability
BID:35700
Info
eBay Enhanced Picture Services ActiveX Control Unspecified Remote Code Execution Vulnerability
| Bugtraq ID: | 35700 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2009 12:00AM |
| Updated: | Jul 15 2009 03:26PM |
| Credit: | unknown |
| Vulnerable: |
eBay Enhanced Picture Services ActiveX control 1.0.27 |
| Not Vulnerable: |
eBay Enhanced Picture Services ActiveX control 1.0.28 |
Discussion
eBay Enhanced Picture Services ActiveX Control Unspecified Remote Code Execution Vulnerability
eBay Enhanced Picture Services ActiveX control is prone to an unspecified remote code-execution vulnerability.
Attackers may exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the affected application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
This issue reportedly affects eBay Enhanced Picture Services ActiveX control 1.0.27 and prior versions.
eBay Enhanced Picture Services ActiveX control is prone to an unspecified remote code-execution vulnerability.
Attackers may exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Successfully exploiting this issue will allow attackers to execute arbitrary code within the context of the affected application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
This issue reportedly affects eBay Enhanced Picture Services ActiveX control 1.0.27 and prior versions.
Exploit / POC
eBay Enhanced Picture Services ActiveX Control Unspecified Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
eBay Enhanced Picture Services ActiveX Control Unspecified Remote Code Execution Vulnerability
Solution:
Reportedly, eBay Enhanced Picture Services ActiveX control 1.0.28 is not affected by this issue.
Solution:
Reportedly, eBay Enhanced Picture Services ActiveX control 1.0.28 is not affected by this issue.
References
eBay Enhanced Picture Services ActiveX Control Unspecified Remote Code Execution Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (eBay)