CSystems WebArchiveX ActiveX Component Arbitrary File Read and Write Vulnerabilities
BID:14760
Info
CSystems WebArchiveX ActiveX Component Arbitrary File Read and Write Vulnerabilities
| Bugtraq ID: | 14760 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2005 12:00AM |
| Updated: | Sep 07 2005 12:00AM |
| Credit: | Discovery is credited to Brett Moore <[email protected]>. |
| Vulnerable: |
CSystems WebArchiveX 5.5 .0.76 |
| Not Vulnerable: | |
Discussion
CSystems WebArchiveX ActiveX Component Arbitrary File Read and Write Vulnerabilities
WebArchiveX is affected by two vulnerabilities that can allow remote attackers to read and write arbitrary files. These issues arise due to a design error as the control is marked "Safe for Scripting" and provides various remotely accessible methods.
WebArchiveX.dll 5.5.0.76 installs prior to September 6th, 2005 are affected by these issues.
WebArchiveX is affected by two vulnerabilities that can allow remote attackers to read and write arbitrary files. These issues arise due to a design error as the control is marked "Safe for Scripting" and provides various remotely accessible methods.
WebArchiveX.dll 5.5.0.76 installs prior to September 6th, 2005 are affected by these issues.
Exploit / POC
CSystems WebArchiveX ActiveX Component Arbitrary File Read and Write Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
CSystems WebArchiveX ActiveX Component Arbitrary File Read and Write Vulnerabilities
Solution:
The current release of WebArchiveX (subsequent to September 6th, 2005) does not mark the component 'Safe for Scripting'. Users are advised to obtain the fixed release from the vendor.
Solution:
The current release of WebArchiveX (subsequent to September 6th, 2005) does not mark the component 'Safe for Scripting'. Users are advised to obtain the fixed release from the vendor.
References
CSystems WebArchiveX ActiveX Component Arbitrary File Read and Write Vulnerabilities
References:
References:
- WebArchiveX Product Page (CSystems)
- WebArchiveX - Unsafe Methods Vulnerability ("Brett Moore"
)