PT-2010-4129 · Realpage · Realpage Module Activex Controls
Publicado
2010-10-26
·
Atualizado
2010-10-28
·
CVE-2010-2584
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RealPage Module ActiveX Controls version 1.0.0.9
Description
The issue concerns the Upload method in the RealPage Module Upload ActiveX control, which does not properly restrict certain property values. This allows remote attackers to read arbitrary files by specifying a filename in the
SourceFile property and an http URL in the DestURL property.Recommendations
For version 1.0.0.9, consider restricting access to the
SourceFile and DestURL properties in the Upload method until a patch is available. As a temporary workaround, avoid using the SourceFile property with http URLs in the DestURL property to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Realpage Module Activex Controls