PT-2010-4129 · Realpage · Realpage Module Activex Controls
Published
2010-10-26
·
Updated
2010-10-28
·
CVE-2010-2584
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RealPage Module ActiveX Controls version 1.0.0.9
Description
The issue concerns the Upload method in the RealPage Module Upload ActiveX control, which does not properly restrict certain property values. This allows remote attackers to read arbitrary files by specifying a filename in the
SourceFile property and an http URL in the DestURL property.Recommendations
For version 1.0.0.9, consider restricting access to the
SourceFile and DestURL properties in the Upload method until a patch is available. As a temporary workaround, avoid using the SourceFile property with http URLs in the DestURL property to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realpage Module Activex Controls