vendor:
CHILKAT ASP String
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
CWE
Product Name: CHILKAT ASP String
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
CHILKAT ASP String (CkString.dll <= 1.1) "SaveToFile()" Insecure Method
This exploit targets the 'SaveToFile()' method in the CHILKAT ASP String (CkString.dll) component, version 1.1 and below. It allows an attacker to execute arbitrary commands on the system, potentially leading to remote code execution. The vulnerability exists in all software that uses this component. The exploit takes advantage of the insecure method to create a malicious batch file ('shinnai.bat') and execute it using 'cmd.exe'.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of the CHILKAT ASP String component. Additionally, restrict access to the component and ensure that it is used securely within the application.