vendor:
ActiveReport ActiveX Control
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
CWE
Product Name: ActiveReport ActiveX Control
Affected Version From: <= 2.5
Affected Version To: <= 2.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
Data Dynamics ActiveReport ActiveX Control (actrpt2.dll <= 2.5) "SaveLayout()" Insecure Method
The exploit overwrites the system.ini file, which can cause the PC to not restart. All software that uses this ocx are vulnerable to this exploit.
Mitigation:
Make a copy of the system.ini file before running this exploit.