vendor:
Clever Internet ActiveX Suite
by:
shinnai
7.5
CVSS
HIGH
Arbitrary file download/overwrite
CWE
Product Name: Clever Internet ActiveX Suite
Affected Version From: 6.2
Affected Version To: 6.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
Clever Internet ActiveX Suite 6.2 (CLINETSUITEX6.OCX) Arbitrary file download/overwrite Exploit
This exploit allows an attacker to download and overwrite files on a vulnerable system using the "GetToFile" method of the CLINETSUITEX6.OCX ActiveX control. The provided code downloads a text file from a remote server and saves it to the local system. The exploit can be modified to overwrite any file on the system, such as cmd.exe.
Mitigation:
Remove or disable the CLINETSUITEX6.OCX ActiveX control. Ensure that all software using this control is updated to a patched version.