CVE-2004-1947
Summary
| CVE | CVE-2004-1947 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-04-19 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Softwin | Bitdefender | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 'BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Softwin BitDefender AvxScanOnlineCtrl COM Object Remote File Upload And Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityTracker.com Archives - BitDefender Scan Online ActiveX Control Lets Remote Users Install and Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| 'Re: BitDefender Scan Online(ActiveX) - Remote File Download &' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| www.osvdb.org/5549 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Secunia - Advisories - AvxScanOnline ActiveX Control Arbitrary File Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Exploit, Vendor Advisory |
| Softwin BitDefender AvxScanOnlineCtrl COM Object Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.