JaguarEdit ActiveX Control Information Disclosure Vulnerability
BID:18576
CVE-2006-3217 |Info
JaguarEdit ActiveX Control Information Disclosure Vulnerability
| Bugtraq ID: | 18576 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2006 12:00AM |
| Updated: | Jun 22 2006 04:15PM |
| Credit: | SRLabs is credited with the discovery of this vulnerability. |
| Vulnerable: |
JaguarSoft JaguarEdit 1.1 .20 JaguarSoft JaguarEdit 1.1 .19 JaguarSoft JaguarEdit 1.1 .18 |
| Not Vulnerable: | |
Discussion
JaguarEdit ActiveX Control Information Disclosure Vulnerability
The JaguarEdit ActiveX control is prone to an information-disclosure vulnerability.
An attacker can exploit this vulnerability to retrieve privileged and potentially sensitive information that may aid in further attacks.
The JaguarEdit ActiveX control is prone to an information-disclosure vulnerability.
An attacker can exploit this vulnerability to retrieve privileged and potentially sensitive information that may aid in further attacks.
Exploit / POC
JaguarEdit ActiveX Control Information Disclosure Vulnerability
Attackers can exploit this vulnerability by tricking a victim user into visiting a malicious site.
Attackers can exploit this vulnerability by tricking a victim user into visiting a malicious site.
Solution / Fix
JaguarEdit ActiveX Control Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
JaguarEdit ActiveX Control Information Disclosure Vulnerability
References:
References: