Xunlei Web Thunder ThunderServer.webThunder.1 ActiveX Control Arbitrary File Download Vulnerability
BID:24552
Info
Xunlei Web Thunder ThunderServer.webThunder.1 ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 24552 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3296 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Sobiny [ BCT ] is credited with the discovery of this vulnerability. |
| Vulnerable: |
Xunlei Web Thunder (ThunderServer.webThunder.1) 1.8.4.130 |
| Not Vulnerable: | |
Discussion
Xunlei Web Thunder ThunderServer.webThunder.1 ActiveX Control Arbitrary File Download Vulnerability
Xunlei Web Thunder ThunderServer.WebThunder.1 ActiveX control is prone to an arbitrary-file-download vulnerability.
An attacker may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
Successful exploits will allow remote attackers to download files from arbitrary locations to the affected computer.
Symantec DeepSight has identified this issue as being actively exploited in the wild in at least one website.
Xunlei Web Thunder ThunderServer.WebThunder.1 ActiveX control is prone to an arbitrary-file-download vulnerability.
An attacker may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
Successful exploits will allow remote attackers to download files from arbitrary locations to the affected computer.
Symantec DeepSight has identified this issue as being actively exploited in the wild in at least one website.
Exploit / POC
Xunlei Web Thunder ThunderServer.webThunder.1 ActiveX Control Arbitrary File Download Vulnerability
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
NOTE: Symantec has observed active, in-the-wild exploits of this issue.
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
NOTE: Symantec has observed active, in-the-wild exploits of this issue.
Solution / Fix
Xunlei Web Thunder ThunderServer.webThunder.1 ActiveX Control Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Xunlei Web Thunder ThunderServer.webThunder.1 ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Xunlei Homepage (Xunlei)
- Web (xunlei) the 0day loophole exposes (whsafe.com)