Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
BID:31227
Info
Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
| Bugtraq ID: | 31227 |
| Class: | Design Error |
| CVE: |
CVE-2008-5089 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Tan Chew Keong |
| Vulnerable: |
Data Dynamics ActiveReports Professional Edition 2.5 .1314 |
| Not Vulnerable: | |
Discussion
Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
Data Dynamics ActiveReports ActiveX control is prone to multiple insecure-method vulnerabilities caused by design errors.
An attacker can exploit these issues to overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Successful exploits will allow attackers to cause denial-of-service conditions; other consequences are possible.
These issues affect Data Dynamics ActiveReports Professional Edition Build 2.5.0.1314 ('ARView2.ocx' version 2.5.0.1314); other versions may also be affected.
Data Dynamics ActiveReports ActiveX control is prone to multiple insecure-method vulnerabilities caused by design errors.
An attacker can exploit these issues to overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Successful exploits will allow attackers to cause denial-of-service conditions; other consequences are possible.
These issues affect Data Dynamics ActiveReports Professional Edition Build 2.5.0.1314 ('ARView2.ocx' version 2.5.0.1314); other versions may also be affected.
Exploit / POC
Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
To exploit these issues, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
Solution / Fix
Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Data Dynamics ActiveReports ARViewer2 ActiveX Control Multiple Insecure Method Vulnerabilities
References:
References:
- Data Dynamics Web Site (Data Dynamics)
- Data Dynamics ActiveReports ARViewer2 ActiveX Control Insecure Methods (Tan Chew Keong)