vendor:
All_IN_THE_BOX ActiveX
by:
Digital Security Research Group [DSecRG]
N/A
CVSS
N/A
Null byte File overwriting
N/A
CWE
Product Name: All_IN_THE_BOX ActiveX
Affected Version From: 3
Affected Version To: 3
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Digital Security Research Group [DSecRG] Advisory #DSECRG-09-006
Synactis All_IN_THE_BOX ActiveX Control (ALL_IN_THE_BOX.OCX) can be used to owervrite any any file in target system. Vulnerable method is "SaveDoc()". By default when saving file All_IN_THE_BOX ActiveX control attend extension to filename variable in "SaveDoc()" method. For example if you enter filename "boot.ini" in "SaveDoc()" method then control will create file boot.ini.box. But by attending a null byte to filename attacker can owervrite any file in OS (see example for owervriting boot.ini).
Mitigation:
No patches available.