Bennet-Tec TList ActiveX Control 'SaveData()' Insecure Method Vulnerability
BID:50476
Info
Bennet-Tec TList ActiveX Control 'SaveData()' Insecure Method Vulnerability
| Bugtraq ID: | 50476 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2011 12:00AM |
| Updated: | Nov 02 2011 07:33PM |
| Credit: | rgod |
| Vulnerable: |
Oracle Hyperion Financial Management 0 Bennet-Tec TList 8.0.26.0 Bennet-Tec TList 6.5.16.0 |
| Not Vulnerable: | |
Discussion
Bennet-Tec TList ActiveX Control 'SaveData()' Insecure Method Vulnerability
Bennet-Tec TList ActiveX control ( 'TList6.ocx') is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to create or overwrite arbitrary files on the victim's computer within the context of the affected application (typically Internet Explorer) that uses the ActiveX control.
Note: This issue was previously titled 'Oracle Hyperion Financial Management 'TList6.ocx' ActiveX Control Insecure Method Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
Bennet-Tec TList ActiveX control ( 'TList6.ocx') is prone to a vulnerability caused by an insecure method.
Successfully exploiting this issue will allow attackers to create or overwrite arbitrary files on the victim's computer within the context of the affected application (typically Internet Explorer) that uses the ActiveX control.
Note: This issue was previously titled 'Oracle Hyperion Financial Management 'TList6.ocx' ActiveX Control Insecure Method Vulnerability'. The title and technical details have been changed to better reflect the underlying component affected.
Exploit / POC
Bennet-Tec TList ActiveX Control 'SaveData()' Insecure Method Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following exploit file is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following exploit file is available:
Solution / Fix
Bennet-Tec TList ActiveX Control 'SaveData()' Insecure Method Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Oracle Hyperion Financial Management 'TList6.ocx' ActiveX Control Insecure Method Vulnerability
References:
References: