vendor:
Barcode ActiveX Control
by:
Cyber-Zone
7.5
CVSS
HIGH
Insecure Method
20
CWE
Product Name: Barcode ActiveX Control
Affected Version From: 3.6.2002
Affected Version To: 3.6.2002
Patch Exists: Yes
Related CWE: N/A
CPE: a:morovia:barcode_activex_control
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
Morovia Barcode ActiveX Control 3.6.2 (MrvBarCd.dll) Insecure Method Exploit
There is an insecure method in the (Save) function of Morovia Barcode ActiveX Control 3.6.2 (MrvBarCd.dll). The exploit can be triggered by clicking a button which calls the Save function and saves a malicious file to the system.
Mitigation:
Update to the latest version of Morovia Barcode ActiveX Control.