vendor:
QRCode ActiveX
by:
shinnai
N/A
CVSS
N/A
Remote File Overwrite
CWE
Product Name: QRCode ActiveX
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2 with Internet Explorer 7
2007
MW6 Technologies QRCode ActiveX 3.0 (MW6QRCode.dll) Remote File Overwrite
This control contains two methods, 'SaveAsBMP()' and 'SaveAsWMF()', which write to a file specified as an argument. These can be exploited to overwrite and corrupt arbitrary files on the system in the context of the currently logged-on user.