Chilkat XML ActiveX Control Multiple Vulnerabilities
BID:31332
Info
Chilkat XML ActiveX Control Multiple Vulnerabilities
| Bugtraq ID: | 31332 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4343 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | shinnai |
| Vulnerable: |
Chilkat ChilkatUtil.dll 3.0.3 .0 |
| Not Vulnerable: | |
Discussion
Chilkat XML ActiveX Control Multiple Vulnerabilities
The Chilkat XML ActiveX control is prone to multiple vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTML page.
Successfully exploiting these issues will allow the attacker to create or overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
The Chilkat XML ActiveX control DLL 'ChilkatUtil.dll' 3.0.3.0 and prior versions are affected.
The Chilkat XML ActiveX control is prone to multiple vulnerabilities.
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTML page.
Successfully exploiting these issues will allow the attacker to create or overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
The Chilkat XML ActiveX control DLL 'ChilkatUtil.dll' 3.0.3.0 and prior versions are affected.
Exploit / POC
Chilkat XML ActiveX Control Multiple Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following proof of concept is available:
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following proof of concept is available:
Solution / Fix
Chilkat XML ActiveX Control Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Chilkat XML ActiveX Control Multiple Vulnerabilities
References:
References:
- Chilkat Software Homepage (Chilkat Software)
- Chilkat XML ActiveX Remote Arbitrary File Creation/Execution (Chilkat)