vendor:
2X ApplicationServer
by:
7.5
CVSS
HIGH
Remote File Overwrite
22
CWE
Product Name: 2X ApplicationServer
Affected Version From: 2X ApplicationServer 10.1
Affected Version To: 2X ApplicationServer 10.1
Patch Exists: NO
Related CWE:
CPE: 2x:applicationserver:10.1
Platforms Tested: Windows Server 2003 r2 sp2, Internet Explorer 8
2X ApplicationServer 10.1 TuxSystem Class ActiveX Control TuxScripting.dll ExportSettings Remote File Overwrite Vulnerability
The 2X ApplicationServer 10.1 TuxSystem ActiveX control allows unsecure file operations (read/write) through the ExportSettings method. By passing an existing file path to ExportSettings, an attacker can overwrite the file with arbitrary content.
Mitigation:
There is currently no known mitigation or remediation for this vulnerability. It is recommended to disable or remove the vulnerable ActiveX control.