vendor:
Document Capture
by:
Evdokimov Dmitriy
7.5
CVSS
HIGH
Insecure Method
264
CWE
Product Name: Document Capture
Affected Version From: Release 10gR3
Affected Version To: Release 10gR3
Patch Exists: YES
Related CWE: CVE-2010-3591
CPE: oracle:document_capture
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
ActiveX components contain insecure methods
Oracle Document Capture contains ActiveX components that contains insecure methods in empop3.dll. Attacker can construct html page which call vulnerable function 'DownloadSingleMessageToFile' from ActiveX component empop3.dll.
Mitigation:
Information was published in CPU Jan 2011