vendor:
PBEmail 7 ActiveX Edition
by:
Katatafish
N/A
CVSS
N/A
Insecure method
CWE
Product Name: PBEmail 7 ActiveX Edition
Affected Version From: PBEmail 7 ActiveX Edition
Affected Version To: PBEmail 7 ActiveX Edition
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2 with Internet Explorer 7
2007
Insecure method in PBEmail 7 ActiveX Edition
The PBEmail 7 ActiveX Edition software is vulnerable to an insecure method, specifically the SaveSenderToXml function in the PBEmail7Ax.dll file. This vulnerability allows an attacker to overwrite arbitrary files on the system, as demonstrated in the provided script.
Mitigation:
It is recommended to update to a patched version of the software, if available. Additionally, restrict access to the affected ActiveX component to trusted sources.