vendor:
Oracle AutoVue
by:
rgod
7.5
CVSS
HIGH
Arbitrary File Creation/Overwrite
Not specified
CWE
Product Name: Oracle AutoVue
Affected Version From: Oracle AutoVue 20.0.1
Affected Version To: Not specified
Patch Exists: NO
Related CWE: Not specified
CPE: Not specified
Platforms Tested:
Not specified
Oracle AutoVue ‘AutoVueX.ocx’ ActiveX Control Insecure Method Arbitrary File Creation/Overwrite
The Oracle AutoVue 'AutoVueX.ocx' ActiveX control is prone to a vulnerability caused by an insecure method. Successfully exploiting this issue will allow attackers to create or overwrite arbitrary files on a victim's computer within the context of the affected application (typically Internet Explorer) that uses the ActiveX control.
Mitigation:
No known mitigation or remediation