vendor:
VImpX
by:
shinnai
8.8
CVSS
HIGH
Buffer Overflow, File Content Deletion, File Content Overwrite
119, 20, 78
CWE
Product Name: VImpX
Affected Version From: 4.8.8.0
Affected Version To: 4.8.8.0
Patch Exists: YES
Related CWE: N/A
CPE: a:db_software_laboratory:vimpx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2009
db Software Laboratory VImpX (VImpX.ocx) Multiple vulnerabilities
db Software Laboratory VImpX (VImpX.ocx) is vulnerable to buffer overflow, file content deletion and file content overwrite. Passing an overly long string (more than 256 bytes) to the LogFile property will lead to a stack based buffer overflow which allows arbitrary code execution. The LogFile() and SaveToFile() methods do not check user supplied arguments, allowing an attacker to delete or overwrite the content of a file. This vulnerability was tested on Windows XP Professional SP3 with Internet Explorer 7.
Mitigation:
Ensure that user supplied arguments are properly validated and sanitized before being used. Update to the latest version of VImpX.ocx.