[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251625

 
 

909

 
 

196370

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-5897Date: (C)2012-11-18   (M)2023-12-22


The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
EXPLOIT-DB-18672
http://archives.neohapsis.com/archives/bugtraq/2012-03/0155.html
SECUNIA-48566
BID-52773
OSVDB-80664
intrust-ardoc-file-overwrite(74442)

CPE    5
cpe:/a:quest:intrust
cpe:/a:quest:intrust:10.1
cpe:/a:quest:intrust:10.3
cpe:/a:quest:intrust:10.4
...
CWE    1
CWE-264
OVAL    1
oval:org.secpod.oval:def:7975

© SecPod Technologies