{"api_version":"1","generated_at":"2026-07-23T06:34:28+00:00","cve":"CVE-2011-0323","urls":{"html":"https://cve.report/CVE-2011-0323","api":"https://cve.report/api/cve/CVE-2011-0323.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0323","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0323"},"summary":{"title":"CVE-2011-0323","description":"Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.","state":"PUBLISHED","assigner":"flexera","published_at":"2011-02-07 21:00:14","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/46128","name":"http://www.securityfocus.com/bid/46128","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SigPlus Pro ActiveX Control Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/secunia_research/2011-1/","name":"http://secunia.com/secunia_research/2011-1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - The Leading Provider of Vulnerability Management and Vulnerability Intelligence Solutions","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/42800","name":"http://secunia.com/advisories/42800","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SigPlus Pro ActiveX Control Multiple Vulnerabilities - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65117","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65117","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0323","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0323","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"323","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"topazsystems","cpe5":"sigplus_pro_activex_control","cpe6":"3.95","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:51:07.805Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"sigplus-sigmessage-file-overwrite(65117)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65117"},{"name":"42800","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42800"},{"name":"46128","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/46128"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2011-1/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-02-03T00:00:00.000Z","descriptions":[{"lang":"en","value":"Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","shortName":"flexera"},"references":[{"name":"sigplus-sigmessage-file-overwrite(65117)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65117"},{"name":"42800","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42800"},{"name":"46128","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/46128"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2011-1/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"PSIRT-CNA@flexerasoftware.com","ID":"CVE-2011-0323","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"sigplus-sigmessage-file-overwrite(65117)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/65117"},{"name":"42800","refsource":"SECUNIA","url":"http://secunia.com/advisories/42800"},{"name":"46128","refsource":"BID","url":"http://www.securityfocus.com/bid/46128"},{"name":"http://secunia.com/secunia_research/2011-1/","refsource":"MISC","url":"http://secunia.com/secunia_research/2011-1/"}]}}}},"cveMetadata":{"assignerOrgId":"44d08088-2bea-4760-83a6-1e9be26b15ab","assignerShortName":"flexera","cveId":"CVE-2011-0323","datePublished":"2011-02-07T20:19:00.000Z","dateReserved":"2011-01-06T00:00:00.000Z","dateUpdated":"2024-08-06T21:51:07.805Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-02-07 21:00:14","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:topazsystems:sigplus_pro_activex_control:3.95:*:*:*:*:*:*:*","matchCriteriaId":"96B79327-3661-43C4-8D46-DE5A995FFF6A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"323","Ordinal":"1","Title":"CVE-2011-0323","CVE":"CVE-2011-0323","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"323","Ordinal":"1","NoteData":"Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content.","Type":"Description","Title":"CVE-2011-0323"},{"CveYear":"2011","CveId":"323","Ordinal":"2","NoteData":"2011-02-07","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"323","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}