PT-2007-6094 · Mw6 Technologies · Mw6 Technologies Qrcode Activex

Shinnai

·

Published

2007-09-19

·

Updated

2017-09-29

·

CVE-2007-4982

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MW6 Technologies QRCode ActiveX versions 3.0.0.1 and earlier
Description The issue allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method of the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll.
Recommendations For versions 3.0.0.1 and earlier, consider disabling the SaveAsBMP and SaveAsWMF methods until a patch is available to prevent exploitation. Restrict access to the MW6QRCode.dll to minimize the risk of arbitrary file creation or overwrite. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4982

Affected Products

Mw6 Technologies Qrcode Activex