PT-2015-3487 · Cygnicon+1 · Cyviewer.Ocx+1

Published

2015-01-01

·

Updated

2015-01-03

·

CVE-2011-5291

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ashampoo 3D CAD Professional versions prior to 3.0.2
Description The issue allows remote attackers to write to arbitrary files. This is achieved by providing a pathname in the first argument to the SaveData method in the Cygnicon.ViewControl.1 ActiveX control in CyViewer.ocx.
Recommendations For versions prior to 3.0.2, update to version 3.0.2 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-5291

Affected Products

Ashampoo 3D Cad Professional
Cyviewer.Ocx