Title : eBay Enhanced Picture Services ActiveX Control Remote Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-2698 CVE ID : CVE-2006-1176
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-07-07
Technical Description
A vulnerability has been identified in eBay Enhanced Picture Services (EPUImageControl Class) ActiveX control, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to a buffer overflow error when handling malformed parameters, which could be exploited by remote attackers to execute arbitrary commands on a vulnerable system via a specially crafted Web page.