Chilkat HTTP 'ChilkatHttp.dll' ActiveX Control Insecure Method Vulnerabilities
BID:28546
Info
Chilkat HTTP 'ChilkatHttp.dll' ActiveX Control Insecure Method Vulnerabilities
| Bugtraq ID: | 28546 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1647 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | shinnai |
| Vulnerable: |
Chilkat Http 2.3 |
| Not Vulnerable: | |
Discussion
Chilkat HTTP 'ChilkatHttp.dll' ActiveX Control Insecure Method Vulnerabilities
Chilkat HTTP ActiveX Control is prone to multiple vulnerabilities that allow attackers to overwrite arbitrary files. These issues affect multiple CLSIDs associated with the control.
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTML page.
Successfully exploiting these issues will allow the attacker to corrupt and overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
Chilkat HTTP ActiveX control 2.3 is vulnerable; other versions may also be affected.
Chilkat HTTP ActiveX Control is prone to multiple vulnerabilities that allow attackers to overwrite arbitrary files. These issues affect multiple CLSIDs associated with the control.
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTML page.
Successfully exploiting these issues will allow the attacker to corrupt and overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
Chilkat HTTP ActiveX control 2.3 is vulnerable; other versions may also be affected.
Exploit / POC
Chilkat HTTP 'ChilkatHttp.dll' ActiveX Control Insecure Method Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example exploit is available:
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example exploit is available:
Solution / Fix
Chilkat HTTP 'ChilkatHttp.dll' ActiveX Control Insecure Method Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Chilkat HTTP 'ChilkatHttp.dll' ActiveX Control Insecure Method Vulnerabilities
References:
References:
- Chilkat Http Homepage (Chilkat)
- Chilkat Software Homepage (Chilkat Software)
- ChilkatHttp ActiveX 2.3 Arbitrary Files Overwrite (shinnai)
- Microsoft Knowledge Base Article 240797 (Microsoft)