Synopsis
The remote Windows host has an ActiveX control that is affected by multiple buffer overflow vulnerabilities.
Description
The remote host contains the PhotoChannel Networks Photo Upload Plugin ActiveX control, which is used by multiple retailers for uploading photographs to photo centers.
The version of this control installed on the remote host reportedly contains multiple and as-yet unspecified overflows that could lead to arbitrary code execution on the affected system. However, successful exploitation requires that an attacker trick a user on the affected host into visiting a specially crafted web page.
Solution
Either upgrade to version 2.0.0.10 or later of the control, disable its use from within Internet Explorer by setting its kill bit, or remove it completely.
Plugin Details
File Name: photochannel_activex_overflows.nasl
Agent: windows
Supported Sensors: Nessus Agent, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
Vulnerability Information
Required KB Items: SMB/Registry/Enumerated
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 9/14/2007