CVE-2007-6530
Last modified
CVE-2007-6530 is a vulnerability of currently unknown severity. Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.. EPSS estimates a 36.83% chance of exploitation in the next 30 days.
Description
Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Groove | Virtual Office | All versions |
| Hp | Loadrunner | All versions |
| Persits | Xupload | 2.1.0.1 |
References
- http://secunia.com/advisories/28145Vendor Advisory
- http://secunia.com/advisories/28205Vendor Advisory
- http://secunia.com/advisories/28218Vendor Advisory
- http://secunia.com/advisories/28145Vendor Advisory
- http://secunia.com/advisories/28205Vendor Advisory
- http://secunia.com/advisories/28218Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6530?
How severe is CVE-2007-6530?
How do I fix CVE-2007-6530?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6524Opera before 9.25 allows remote attackers to obtain potentia…
- CVE-2007-6525Unspecified vulnerability in eClient in IBM DB2 Content Mana…
- CVE-2007-6526Cross-site scripting (XSS) vulnerability in tiki-special_cha…
- CVE-2007-6527uploadimg.php in the Automatic Image Upload with Thumbnails …
- CVE-2007-6528Directory traversal vulnerability in tiki-listmovies.php in …
- CVE-2007-6529Multiple unspecified vulnerabilities in TikiWiki before 1.9.…
- CVE-2007-6531Stack-based buffer overflow in the Panel (xfce4-panel) compo…
- CVE-2007-6532Double free vulnerability in the Widget Library (libxfcegui4…
- CVE-2007-6533Buffer overflow in Zoom Player 6.00 beta 2 and earlier allow…
- CVE-2007-6534Multiple unspecified vulnerabilities in Microsoft Office Pub…
- CVE-2007-6535Buffer overflow in the YShortcut ActiveX control in YShortcu…
- CVE-2007-6536The Custom Button Installer dialog in Google Toolbar 4 and 5…
Are you affected by CVE-2007-6530?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
