Sina DLoader Class ActiveX Control 'DonwloadAndInstall' Method Arbitrary File Download Vulnerability
BID:30223
Info
Sina DLoader Class ActiveX Control 'DonwloadAndInstall' Method Arbitrary File Download Vulnerability
| Bugtraq ID: | 30223 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6442 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2008 12:00AM |
| Updated: | May 07 2015 05:27PM |
| Credit: | Symantec Security Intelligence Analysis Team discovered this issue via Honeypot Analysis. |
| Vulnerable: |
Sina Inc. DLoader 0 |
| Not Vulnerable: | |
Discussion
Sina DLoader Class ActiveX Control 'DonwloadAndInstall' Method Arbitrary File Download Vulnerability
Sina DLoader is prone to a vulnerability that can cause malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to overwrite sensitive files with malicious data that will compromise the affected computer. Other attacks are possible.
Sina DLoader is prone to a vulnerability that can cause malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to overwrite sensitive files with malicious data that will compromise the affected computer. Other attacks are possible.
Exploit / POC
Sina DLoader Class ActiveX Control 'DonwloadAndInstall' Method Arbitrary File Download Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
The following exploit code is available:
Solution / Fix
Sina DLoader Class ActiveX Control 'DonwloadAndInstall' Method Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sina DLoader Class ActiveX Control 'DonwloadAndInstall' Method Arbitrary File Download Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Sina UC Homepage (Sina Inc.)