« Volver al listado

CVE-2008-4729

Estado: ModificadaMedia (6.8)—

Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-4729",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-10-24T00:00:00.977",
  "references": [
    {
      "url": "http://secunia.com/advisories/32319",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/4505",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/31783",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45941",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/6761",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/32319",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/4505",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/31783",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45941",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/6761",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property.  NOTE: code execution might not be possible in 13.0."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en la pila en el control ActiveX de Hummingbird.XWebHostCtrl.1(hclxweb.dll) en Hummingbird Xweb ActiveX Control v13.0 y anteriores que permite a atacantes remotos ejecutar código de su elección a traves de la propiedad PlanTextPassword. NOTA: La ejecución de código podria no ser posible en la v13.0."
    }
  ],
  "lastModified": "2026-06-16T22:58:24.180",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hummingbird:exceed:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "044CA4D8-ACF2-4CDC-A51B-0FC63DAC4918",
              "versionEndIncluding": "13.0"
            },
            {
              "criteria": "cpe:2.3:a:hummingbird:exceed:9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C3F1215-D202-4783-A350-5E27952D7620"
            },
            {
              "criteria": "cpe:2.3:a:hummingbird:exceed:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8742368E-B84F-444D-B791-7920028F0798"
            },
            {
              "criteria": "cpe:2.3:a:hummingbird:exceed:2006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61317B48-4B10-46D0-B37C-60CDAC9FAE0F"
            },
            {
              "criteria": "cpe:2.3:a:hummingbird:exceed:2007:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C73870B-FD87-4628-9F22-23554D7BB9D5"
            },
            {
              "criteria": "cpe:2.3:a:hummingbird:exceed_powersuite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97D9D378-3C28-4D1F-9D86-7AAE4C04F005"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}