vendor:
ActiveBar ActiveX Control
by:
shinnai
9.3
CVSS
HIGH
Multiple Insecure Methods
264
CWE
Product Name: ActiveBar ActiveX Control
Affected Version From: 3.2
Affected Version To: 3.2
Patch Exists: Yes
Related CWE: N/A
CPE: a:datadynamics:activebar_activex_control
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008
Data Dynamics ActiveBar ActiveX Control (Actbar3.ocx 3.2) Multiple Inscure Methods
Data Dynamics ActiveBar ActiveX Control (Actbar3.ocx 3.2) is vulnerable to multiple insecure methods. An attacker can exploit this vulnerability by using a malicious VBScript code to execute arbitrary code on the vulnerable system. The vulnerable methods are Save, SaveLayoutChanges and SaveMenuUsageData. An attacker can use these methods to write arbitrary files to the system.
Mitigation:
Update to the latest version of Data Dynamics ActiveBar ActiveX Control (Actbar3.ocx 3.2).