vendor:
Magneto ICMP ActiveX
by:
boahat
9.3
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Magneto ICMP ActiveX
Affected Version From: 4.0.0.20
Affected Version To: 4.0.0.20
Patch Exists: YES
Related CWE: N/A
CPE: a:magnetosoft:magneto_icmp_activex
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Magneto ICMP ActiveX v4.0.0.20 ICMPSendEchoRequest Remote Code Execute
A vulnerability in Magneto ICMP ActiveX v4.0.0.20 allows remote attackers to execute arbitrary code via a crafted web page. The vulnerability exists in the ICMPSendEchoRequest function of SKIcmp.ocx, which can be exploited to control the edx register. An attacker can leverage this vulnerability to execute arbitrary code in the context of the user running the affected application.
Mitigation:
Upgrade to the latest version of Magneto ICMP ActiveX, 5.0.0.1, which contains the fix.