GeoVision LiveX ActiveX Control 'SnapShotToFile()' Arbitrary File Overwrite Vulnerability
BID:33782
Info
GeoVision LiveX ActiveX Control 'SnapShotToFile()' Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 33782 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0865 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2009 12:00AM |
| Updated: | Apr 13 2015 09:11PM |
| Credit: | Nine:Situations:Group::SnoopyAssault |
| Vulnerable: |
GeoVision LiveX ActiveX Control 8200 GeoVision LiveX ActiveX Control 8120 GeoVision LiveX ActiveX Control 7000 |
| Not Vulnerable: | |
Discussion
GeoVision LiveX ActiveX Control 'SnapShotToFile()' Arbitrary File Overwrite Vulnerability
GeoVision LiveX ActiveX control is prone to a vulnerability that lets attackers overwrite files with arbitrary, attacker-controlled content.
An attacker can exploit this issue to corrupt and overwrite arbitrary files on a victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
GeoVision LiveX ActiveX control 7000, 8120, and 8200 are vulnerable; other versions may also be affected.
GeoVision LiveX ActiveX control is prone to a vulnerability that lets attackers overwrite files with arbitrary, attacker-controlled content.
An attacker can exploit this issue to corrupt and overwrite arbitrary files on a victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
GeoVision LiveX ActiveX control 7000, 8120, and 8200 are vulnerable; other versions may also be affected.
Exploit / POC
GeoVision LiveX ActiveX Control 'SnapShotToFile()' Arbitrary File Overwrite Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
The following exploit is available:
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
The following exploit is available:
Solution / Fix
GeoVision LiveX ActiveX Control 'SnapShotToFile()' Arbitrary File Overwrite Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
GeoVision LiveX ActiveX Control 'SnapShotToFile()' Arbitrary File Overwrite Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (GeoVision)