IBiz E-Banking Integrator ActiveX Control 'WriteOFXDataFile()' Insecure Method Vulnerability
BID:28700
Info
IBiz E-Banking Integrator ActiveX Control 'WriteOFXDataFile()' Insecure Method Vulnerability
| Bugtraq ID: | 28700 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1725 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | shinnai <shinnai[at]autistici[dot]org> |
| Vulnerable: |
/n software IBiz E-Banking Integrator 2.0 |
| Not Vulnerable: | |
Discussion
IBiz E-Banking Integrator ActiveX Control 'WriteOFXDataFile()' Insecure Method Vulnerability
An IBiz E-Banking Integrator ActiveX control is prone to a vulnerability that allows attackers to create or overwrite arbitrary data with the privileges of the application using the control (typically Internet Explorer).
Successful exploits can compromise affected computers or cause denial-of-service conditions; other attacks are possible.
IBiz E-Banking Integrator 2.0 is vulnerable; other versions may also be affected.
An IBiz E-Banking Integrator ActiveX control is prone to a vulnerability that allows attackers to create or overwrite arbitrary data with the privileges of the application using the control (typically Internet Explorer).
Successful exploits can compromise affected computers or cause denial-of-service conditions; other attacks are possible.
IBiz E-Banking Integrator 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
IBiz E-Banking Integrator ActiveX Control 'WriteOFXDataFile()' Insecure Method Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web document.
The following proof of concept is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web document.
The following proof of concept is available:
Solution / Fix
IBiz E-Banking Integrator ActiveX Control 'WriteOFXDataFile()' Insecure Method Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IBiz E-Banking Integrator ActiveX Control 'WriteOFXDataFile()' Insecure Method Vulnerability
References:
References:
- IBiz E-Banking Integrator Homepage (/n software)
- Microsoft Knowledge Base Article 240797 (Microsoft)