CVE-2012-5897
Summary
| CVE | CVE-2012-5897 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-17 21:55:00 UTC |
| Updated | 2017-09-02 01:29:00 UTC |
| Description | The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Quest | Intrust | 10.1 | All | All | All |
| Application | Quest | Intrust | 10.2.5 | All | All | All |
| Application | Quest | Intrust | 10.3 | All | All | All |
| Application | Quest | Intrust | 10.4 | All | All | All |
| Application | Quest | Intrust | 10.1 | All | All | All |
| Application | Quest | Intrust | 10.2.5 | All | All | All |
| Application | Quest | Intrust | 10.3 | All | All | All |
| Application | Quest | Intrust | 10.4 | All | All | All |
| Application | Quest | Intrust | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Quest InTrust 'ArDoc.dll' Multiple Insecure Method Vulnerabilities | BID | www.securityfocus.com | Exploit |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Security Advisory SA48566 - Quest InTrust ActiveX Controls Multiple Vulnerabilities - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 80664 | OSVDB | osvdb.org | |
| Quest InTrust 10.4.x ReportTree and SimpleTree Classes | EXPLOIT-DB | www.exploit-db.com | Exploit |
| 20120328 Quest InTrust 10.4.x ReportTree and SimpleTree Classes ArDoc.dll ActiveX Control Remote File Creation / Overwrite Vulnerability | BUGTRAQ | archives.neohapsis.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.