CygniCon CyViewer ActiveX Control 'SaveData()' Insecure Method Vulnerability
BID:48483
Info
CygniCon CyViewer ActiveX Control 'SaveData()' Insecure Method Vulnerability
| Bugtraq ID: | 48483 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2011 12:00AM |
| Updated: | Jun 28 2011 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
CygniCon CyViewer 0 Ashampoo 3D CAD Professional 3 3.0.1 |
| Not Vulnerable: | |
Discussion
CygniCon CyViewer ActiveX Control 'SaveData()' Insecure Method Vulnerability
CygniCon CyViewer ActiveX control is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to create or overwrite files within the context of the affected application (typically Internet Explorer) that uses the ActiveX control. Attackers may execute arbitrary code with user-level privileges.
CygniCon CyViewer ActiveX control is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to create or overwrite files within the context of the affected application (typically Internet Explorer) that uses the ActiveX control. Attackers may execute arbitrary code with user-level privileges.
Exploit / POC
CygniCon CyViewer ActiveX Control 'SaveData()' Insecure Method Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following sample code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following sample code is available:
Solution / Fix
CygniCon CyViewer ActiveX Control 'SaveData()' Insecure Method Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CygniCon CyViewer ActiveX Control 'SaveData()' Insecure Method Vulnerability
References:
References:
- Ashampoo 3D CAD Professional 3 (Ashampoo)
- Ashampoo 3D CAD Professional 3 ActiveX control Insecure Method (High-Tech Bridge SA)
- CygniCon Homepage (CygniCon)
- Ashampoo 3D CAD Professional 3 ActiveX control Insecure Method (High-Tech Bridge SA)