BlooMooWeb ActiveX Control Multiple Vulnerabilities
BID:20827
Info
BlooMooWeb ActiveX Control Multiple Vulnerabilities
| Bugtraq ID: | 20827 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2006 12:00AM |
| Updated: | Nov 02 2006 12:42AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Studio achtundachtzig BlooMooWeb ActiveX Control 1.0.9 |
| Not Vulnerable: | |
Discussion
BlooMooWeb ActiveX Control Multiple Vulnerabilities
BlooMooWeb ActiveX control is prone to multiple vulnerabilities, including:
- an arbitrary file-download issue
- an arbitrary code-execution issue
- an arbitrary file-deletion issue.
An attacker can exploit these issues to download arbitrary files, execute arbitrary code within the context of the affected application, and delete arbitrary files.
BlooMooWeb ActiveX control is prone to multiple vulnerabilities, including:
- an arbitrary file-download issue
- an arbitrary code-execution issue
- an arbitrary file-deletion issue.
An attacker can exploit these issues to download arbitrary files, execute arbitrary code within the context of the affected application, and delete arbitrary files.
Exploit / POC
BlooMooWeb ActiveX Control Multiple Vulnerabilities
The following exploit code is available:
The following exploit code is available:
Solution / Fix
BlooMooWeb ActiveX Control Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
BlooMooWeb ActiveX Control Multiple Vulnerabilities
References:
References:
- Vendor Home Page (Studio achtundachtzig)
- ActiveX security leaks in the TV owned web game platform ([email protected])