{"api_version":"1","generated_at":"2026-04-23T05:14:02+00:00","cve":"CVE-2004-1947","urls":{"html":"https://cve.report/CVE-2004-1947","api":"https://cve.report/api/cve/CVE-2004-1947.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1947","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1947"},"summary":{"title":"CVE-2004-1947","description":"The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-04-19 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://marc.info/?l=bugtraq&m=108240639427412&w=2","name":"http://marc.info/?l=bugtraq&m=108240639427412&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10174","name":"http://www.securityfocus.com/bid/10174","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Softwin BitDefender AvxScanOnlineCtrl COM Object Remote File Upload And Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1009862","name":"http://securitytracker.com/id?1009862","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - BitDefender Scan Online ActiveX Control Lets Remote Users Install and Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15911","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15911","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=108248367901616&w=2","name":"http://marc.info/?l=bugtraq&m=108248367901616&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Re: BitDefender Scan Online(ActiveX) - Remote File Download &' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/5549","name":"http://www.osvdb.org/5549","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/11427","name":"http://secunia.com/advisories/11427","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"Secunia - Advisories - AvxScanOnline ActiveX Control Arbitrary File Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/10175","name":"http://www.securityfocus.com/bid/10175","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Softwin BitDefender AvxScanOnlineCtrl COM Object Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1947","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1947","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1947","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"softwin","cpe5":"bitdefender","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:07:49.138Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"bitdefender-avxscanonline-code-execution(15911)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15911"},{"name":"10174","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10174"},{"name":"20040420 Re: BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108248367901616&w=2"},{"name":"11427","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/11427"},{"name":"10175","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/10175"},{"name":"1009862","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1009862"},{"name":"5549","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/5549"},{"name":"20040419 BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108240639427412&w=2"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-04-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"bitdefender-avxscanonline-code-execution(15911)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15911"},{"name":"10174","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10174"},{"name":"20040420 Re: BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108248367901616&w=2"},{"name":"11427","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/11427"},{"name":"10175","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/10175"},{"name":"1009862","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1009862"},{"name":"5549","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/5549"},{"name":"20040419 BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108240639427412&w=2"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1947","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"bitdefender-avxscanonline-code-execution(15911)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15911"},{"name":"10174","refsource":"BID","url":"http://www.securityfocus.com/bid/10174"},{"name":"20040420 Re: BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108248367901616&w=2"},{"name":"11427","refsource":"SECUNIA","url":"http://secunia.com/advisories/11427"},{"name":"10175","refsource":"BID","url":"http://www.securityfocus.com/bid/10175"},{"name":"1009862","refsource":"SECTRACK","url":"http://securitytracker.com/id?1009862"},{"name":"5549","refsource":"OSVDB","url":"http://www.osvdb.org/5549"},{"name":"20040419 BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108240639427412&w=2"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1947","datePublished":"2005-05-10T04:00:00.000Z","dateReserved":"2005-05-04T00:00:00.000Z","dateUpdated":"2024-08-08T01:07:49.138Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-04-19 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:softwin:bitdefender:*:*:*:*:*:*:*:*","matchCriteriaId":"E66C8032-485B-4B96-93A6-93BC051DCE2A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1947","Ordinal":"1","Title":"CVE-2004-1947","CVE":"CVE-2004-1947","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1947","Ordinal":"1","NoteData":"The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab.","Type":"Description","Title":"CVE-2004-1947"},{"CveYear":"2004","CveId":"1947","Ordinal":"2","NoteData":"2005-05-10","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1947","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}