CVE-2004-1947
Summary
| CVE | CVE-2004-1947 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-04-19 04:00:00 UTC |
| Updated | 2017-07-11 01:31:00 UTC |
| Description | The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Softwin | Bitdefender | All | All | All | All |
| Application | Softwin | Bitdefender | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure' - MARC | BUGTRAQ | marc.info | |
| 'Re: BitDefender Scan Online(ActiveX) - Remote File Download &' - MARC | BUGTRAQ | marc.info | |
| Secunia - Advisories - AvxScanOnline ActiveX Control Arbitrary File Execution Vulnerability | SECUNIA | secunia.com | Exploit, Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| 5549 | OSVDB | www.osvdb.org | |
| Softwin BitDefender AvxScanOnlineCtrl COM Object Information Disclosure Vulnerability | BID | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| Softwin BitDefender AvxScanOnlineCtrl COM Object Remote File Upload And Execution Vulnerability | BID | www.securityfocus.com | |
| SecurityTracker.com Archives - BitDefender Scan Online ActiveX Control Lets Remote Users Install and Execute Arbitrary Code | SECTRACK | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.