PT-2011-2272 · Dell · Dellsystemlite.Ocx
Published
2011-02-21
·
Updated
2011-03-18
·
CVE-2011-0329
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
DellSystemLite.ocx version 1.0.0.0
Description
The issue allows remote attackers to read arbitrary files via directory traversal sequences in the
fileID parameter of the GetData method in the DellSystemLite.Scanner ActiveX control.Recommendations
For DellSystemLite.ocx version 1.0.0.0, avoid using the
fileID parameter in the GetData method until the issue is resolved. Consider restricting access to the DellSystemLite.Scanner ActiveX control to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dellsystemlite.Ocx