iMesh 'IMWebControl' ActiveX Control Code Execution Vulnerability
BID:26916
Info
iMesh 'IMWebControl' ActiveX Control Code Execution Vulnerability
| Bugtraq ID: | 26916 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6493 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2007 12:00AM |
| Updated: | Nov 04 2008 07:45PM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
iMesh iMesh 7.1.0.37263 iMesh iMesh 7 |
| Not Vulnerable: | |
Discussion
iMesh 'IMWebControl' ActiveX Control Code Execution Vulnerability
iMesh is prone to a code-execution vulnerability because the application fails to sanitize user-supplied data, which can lead to memory corruption.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using an affected ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
iMesh 7.1.0.37263 and prior versions are reported affected by this issue.
iMesh is prone to a code-execution vulnerability because the application fails to sanitize user-supplied data, which can lead to memory corruption.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using an affected ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
iMesh 7.1.0.37263 and prior versions are reported affected by this issue.
Exploit / POC
iMesh 'IMWebControl' ActiveX Control Code Execution Vulnerability
Reports indicate that this issue is being exploited in the wild.
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web
document.
The following exploit is available:
Reports indicate that this issue is being exploited in the wild.
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web
document.
The following exploit is available:
Solution / Fix
iMesh 'IMWebControl' ActiveX Control Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
iMesh 'IMWebControl' ActiveX Control Code Execution Vulnerability
References:
References: