PT-2009-2827 · Aaa · Aaa Easygrid Activex
Houssamix
·
Publicado
2009-01-16
·
Atualizado
2017-09-29
·
CVE-2009-0134
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AAA EasyGrid ActiveX version 3.51
Description
The issue concerns an insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control. This vulnerability allows remote attackers to create and overwrite arbitrary files. Attackers can leverage this issue via the
DoSaveFile or DoSaveHtmlFile method. It is noted that this vulnerability could potentially be used for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs.Recommendations
For AAA EasyGrid ActiveX version 3.51, consider disabling the
DoSaveFile and DoSaveHtmlFile methods as a temporary workaround until a patch is available. Restrict access to the EasyGrid.SGCtrl.32 ActiveX control to minimize the risk of exploitation. Avoid using the EasyGrid.SGCtrl.32 ActiveX control in sensitive environments until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Aaa Easygrid Activex