LEADTOOLS Imaging LEADSmtp ActiveX Control 'SaveMessage()' Insecure Method Vulnerability
BID:48408
Info
LEADTOOLS Imaging LEADSmtp ActiveX Control 'SaveMessage()' Insecure Method Vulnerability
| Bugtraq ID: | 48408 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2011 12:00AM |
| Updated: | Jun 23 2011 12:00AM |
| Credit: | High-Tech Bridge SA and Secunia Research. |
| Vulnerable: |
LeadTools Imaging ActiveX 0 Kofax Kofax e-Transactions 2.5.0.933 |
| Not Vulnerable: | |
Discussion
LEADTOOLS Imaging LEADSmtp ActiveX Control 'SaveMessage()' Insecure Method Vulnerability
LEADTOOLS Imaging LEADSmtp ActiveX control is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to create or overwrite files within the context of the affected application (typically Internet Explorer) that uses the ActiveX control. Attackers may execute arbitrary code with user-level privileges.
LEADTOOLS Imaging LEADSmtp ActiveX control is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to create or overwrite files within the context of the affected application (typically Internet Explorer) that uses the ActiveX control. Attackers may execute arbitrary code with user-level privileges.
Exploit / POC
LEADTOOLS Imaging LEADSmtp ActiveX Control 'SaveMessage()' Insecure Method Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following sample code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following sample code is available:
Solution / Fix
LEADTOOLS Imaging LEADSmtp ActiveX Control 'SaveMessage()' Insecure Method Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
LEADTOOLS Imaging LEADSmtp ActiveX Control 'SaveMessage()' Insecure Method Vulnerability
References:
References:
- HTB23016: Kofax e-Transactions Sender Sendbox ActiveX Control Insecure Method (High-Tech Bridge SA)
- Kofax e-Transactions (Kofax)
- LEADTOOLS Imaging ActiveX (LEADTOOLS)