C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability
BID:29519
Info
C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 29519 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2008 12:00AM |
| Updated: | Feb 03 2012 08:00AM |
| Credit: | Nine:Situations:Group::SnoopyAssault |
| Vulnerable: |
Telecom Italia Group C6 Messenger 0 |
| Not Vulnerable: | |
Discussion
C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability
C6 Messenger Installation URL Downloader ActiveX control is prone to a vulnerability that lets remote attackers download files from arbitrary locations to an affected computer.
Attackers may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
C6 Messenger Installation URL Downloader ActiveX control is prone to a vulnerability that lets remote attackers download files from arbitrary locations to an affected computer.
Attackers may exploit this issue by enticing victims into visiting a maliciously crafted webpage.
Exploit / POC
C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
UPDATE (August 11, 2008): Symantec has detected active exploit attempts in the wild.
The following exploits are available:
Attackers may exploit this issue by enticing victims into opening a maliciously crafted webpage.
UPDATE (August 11, 2008): Symantec has detected active exploit attempts in the wild.
The following exploits are available:
Solution / Fix
C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
C6 Messenger Installation URL Downloader ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- C6 Messenger Homepage (Telecom Italia Group)
- Microsoft Knowledge Base Article 240797 (Microsoft)