EMC Captiva eInput ActiveX Function Insecure Method Vulnerability
BID:48904
Info
EMC Captiva eInput ActiveX Function Insecure Method Vulnerability
| Bugtraq ID: | 48904 |
| Class: | Design Error |
| CVE: |
CVE-2011-1744 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2011 12:00AM |
| Updated: | Jul 27 2011 12:00AM |
| Credit: | EMC |
| Vulnerable: |
EMC Captiva eInput 2.1.1 EMC Captiva eInput 2.1 EMC Captiva eInput 2.0 EMC Captiva eInput 1.1 |
| Not Vulnerable: |
EMC Captiva eInput 2.1.2 |
Discussion
EMC Captiva eInput ActiveX Function Insecure Method Vulnerability
The EMC Captiva eInput is prone to an insecure method vulnerability.
Successful exploits will allow remote attackers to read arbitrary data from or cause a denial-of-service condition.
EMC Captiva eInput 2.1.1 is vulnerable; other versions may also be affected.
The EMC Captiva eInput is prone to an insecure method vulnerability.
Successful exploits will allow remote attackers to read arbitrary data from or cause a denial-of-service condition.
EMC Captiva eInput 2.1.1 is vulnerable; other versions may also be affected.
Exploit / POC
EMC Captiva eInput ActiveX Function Insecure Method Vulnerability
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious web document.
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious web document.
Solution / Fix
EMC Captiva eInput ActiveX Function Insecure Method Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
EMC Captiva eInput ActiveX Function Insecure Method Vulnerability
References:
References:
- EMC Homepage (EMC)
- ZDI-10-020: EMC HomeBase SSL Service Arbitrary File Upload Remote Code Execution (Zero Day Initiative)