Retired: Blackice Cover Page 'DownloadImageFileURL()' Arbitrary File Download Vulnerability
BID:48343
Info
Retired: Blackice Cover Page 'DownloadImageFileURL()' Arbitrary File Download Vulnerability
| Bugtraq ID: | 48343 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2011 12:00AM |
| Updated: | Jul 21 2011 04:00PM |
| Credit: | mr_me |
| Vulnerable: |
Black Ice Software Cover Page 0 |
| Not Vulnerable: | |
Discussion
Retired: Blackice Cover Page 'DownloadImageFileURL()' Arbitrary File Download Vulnerability
Blackice Cover Page is prone to a vulnerability that can cause malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to put malicious files in arbitrary locations on a victim's computer. Successful exploits will allow attackers to execute arbitrary code within the context of the currently logged-in user.
Further analysis indicates that this issue was reported in BID 29577 (Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability) therefore this BID is being retired.
Blackice Cover Page is prone to a vulnerability that can cause malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Attackers may exploit this issue to put malicious files in arbitrary locations on a victim's computer. Successful exploits will allow attackers to execute arbitrary code within the context of the currently logged-in user.
Further analysis indicates that this issue was reported in BID 29577 (Black Ice Multiple Applications 'BiDib.dll' ActiveX Control Arbitrary File Download Vulnerability) therefore this BID is being retired.
Exploit / POC
Retired: Blackice Cover Page 'DownloadImageFileURL()' Arbitrary File Download Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Retired: Blackice Cover Page 'DownloadImageFileURL()' Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Retired: Blackice Cover Page 'DownloadImageFileURL()' Arbitrary File Download Vulnerability
References:
References:
- Vendor Homepage (Black Ice Software)