SupportSoft DNA Editor Module ActiveX Control Insecure Method Remote Code Execution Vulnerability
BID:34004
Info
SupportSoft DNA Editor Module ActiveX Control Insecure Method Remote Code Execution Vulnerability
| Bugtraq ID: | 34004 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2009 12:00AM |
| Updated: | Mar 06 2009 06:56PM |
| Credit: | Nine:Situations:Group::bruiser |
| Vulnerable: |
SupportSoft DNA Editor Module 0 |
| Not Vulnerable: | |
Discussion
SupportSoft DNA Editor Module ActiveX Control Insecure Method Remote Code Execution Vulnerability
SupportSoft DNA Editor Module ActiveX control is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied input.
Successfully exploiting this issue allows an attacker to execute arbitrary code in the context of the application running the affected control (typically Internet Explorer).
This issue affects DNA Editor Module provided by 'dnaedit.dll' 6.9.2205.
SupportSoft DNA Editor Module ActiveX control is prone to a remote code-execution vulnerability because it fails to adequately validate user-supplied input.
Successfully exploiting this issue allows an attacker to execute arbitrary code in the context of the application running the affected control (typically Internet Explorer).
This issue affects DNA Editor Module provided by 'dnaedit.dll' 6.9.2205.
Exploit / POC
SupportSoft DNA Editor Module ActiveX Control Insecure Method Remote Code Execution Vulnerability
To exploit this issue, attackers must entice an unsuspecting user into viewing a malicious webpage.
The following exploit code is available:
To exploit this issue, attackers must entice an unsuspecting user into viewing a malicious webpage.
The following exploit code is available:
Solution / Fix
SupportSoft DNA Editor Module ActiveX Control Insecure Method Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SupportSoft DNA Editor Module ActiveX Control Insecure Method Remote Code Execution Vulnerability
References:
References: