Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 07:44:29 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1463268725&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2Ffiledesc%2Fultraoffice_httpupload.rb.txt.html%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1463268725.1338191069.1338191069.1338191069.1%3B%2B__utmz%3D32867617.1338191069.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Ultra Shareware Office Control ActiveX HttpUpload Buffer Overflow http://packetstormsecurity.org/files/86916/ultraoffice_httpupload.rb.txt http://packetstormsecurity.org/files/86916/ultraoffice_httpupload.rb.txt http://packetstormsecurity.org/files/86916/Ultra-Shareware-Office-Control-ActiveX-HttpUpload-Buffer-Overflow.html Fri, 05 Mar 2010 03:53:30 GMT This Metasploit module exploits a stack-based buffer overflow in Ultra Shareware's Office Control. When processing the 'HttpUpload' method, the arguments are concatenated together to form a command line to run a bundled version of cURL. If the command fails to run, a stack-based buffer overflow occurs when building the error message. This is due to the use of sprintf() without proper bounds checking. NOTE: Due to input restrictions, this exploit uses a heap-spray to get the payload into memory unmodified.