Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
BID:25063
Info
Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
| Bugtraq ID: | 25063 |
| Class: | Design Error |
| CVE: |
CVE-2007-4067 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2007 12:00AM |
| Updated: | May 07 2015 05:36PM |
| Credit: | shinnai is credited with the discovery of this vulnerability. |
| Vulnerable: |
Clever Components Clever Internet ActiveX Suite 6.2 |
| Not Vulnerable: | |
Discussion
Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
Clever Internet ActiveX Suite ActiveX control is prone to an arbitrary file-overwrite vulnerability due to a design error.
An attacker can exploit this issue to overwrite or download arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Successful exploits will allow attackers to cause denial-of-service conditions or to access sensitive information; other consequences are possible.
This issue affects Clever Internet ActiveX Suite 6.2; other versions may also be affected.
Clever Internet ActiveX Suite ActiveX control is prone to an arbitrary file-overwrite vulnerability due to a design error.
An attacker can exploit this issue to overwrite or download arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Successful exploits will allow attackers to cause denial-of-service conditions or to access sensitive information; other consequences are possible.
This issue affects Clever Internet ActiveX Suite 6.2; other versions may also be affected.
Exploit / POC
Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
UPDATE (Aug. 11, 2008): Symantec has detected active exploit attempts in the wild.
The following exploit is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
UPDATE (Aug. 11, 2008): Symantec has detected active exploit attempts in the wild.
The following exploit is available:
Solution / Fix
Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Clever Internet ActiveX Suite CLINetSuiteX6.OCX Arbitrary File Download Or Overwrite Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (Clever Components)