The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlideShow method.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://osvdb.org/40628 | vdb entry |
https://www.exploit-db.com/exploits/4981 | exploit |
http://secunia.com/advisories/28644 | third party advisory vendor advisory |
http://securityreason.com/securityalert/4410 | third party advisory |
http://www.securityfocus.com/archive/1/486941/100/200/threaded | mailing list |
http://www.securityfocus.com/bid/27439 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39921 | vdb entry |