PT-2008-5960 · Db Software Laboratory · Vimp X
Shinnai
·
Publicado
2008-10-27
·
Atualizado
2017-09-29
·
CVE-2008-4749
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DB Software Laboratory VImp X versions 4.7.7 through 4.8.8.0
Description
The issue concerns insecure methods in the VImpX.VImpAX ActiveX control, allowing remote attackers to overwrite arbitrary files. This can be achieved via the
LogFile property and ClearLogFile method, as well as the SaveToFile method.Recommendations
For version 4.7.7, consider disabling the
ClearLogFile method and restricting access to the SaveToFile method until a fix is available.
For version 4.8.8.0, avoid using the LogFile property and restrict access to the SaveToFile method until a patch is applied.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vimp X