vendor:
Barcode ActiveX Professional
by:
shinnai
7.5
CVSS
HIGH
Arbitrary file overwrite
22
CWE
Product Name: Barcode ActiveX Professional
Affected Version From: 3.3 (build 1304)
Affected Version To: 3.3 (build 1304)
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2007
Morovia Barcode ActiveX Professional 3.3 (build 1304) Arbitrary file overwrite
The exploit overwrites the system.ini file, potentially causing the PC to not restart. It affects Morovia Barcode ActiveX Professional 3.3 (build 1304) on Windows XP Professional SP2 with Internet Explorer 7.
Mitigation:
Make a copy of the system.ini file before running the exploit.