PT-2009-2827 · Aaa · Aaa Easygrid Activex

Houssamix

·

Published

2009-01-16

·

Updated

2017-09-29

·

CVE-2009-0134

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AAA EasyGrid ActiveX version 3.51
Description The issue concerns an insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control. This vulnerability allows remote attackers to create and overwrite arbitrary files. Attackers can leverage this issue via the DoSaveFile or DoSaveHtmlFile method. It is noted that this vulnerability could potentially be used for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs.
Recommendations For AAA EasyGrid ActiveX version 3.51, consider disabling the DoSaveFile and DoSaveHtmlFile methods as a temporary workaround until a patch is available. Restrict access to the EasyGrid.SGCtrl.32 ActiveX control to minimize the risk of exploitation. Avoid using the EasyGrid.SGCtrl.32 ActiveX control in sensitive environments until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-0134

Affected Products

Aaa Easygrid Activex