vendor:
Rediff Bol Downloader ActiveX
by:
Gregory R. Panakkal
7,5
CVSS
HIGH
ActiveX (OCX) Control
N/A
CWE
Product Name: Rediff Bol Downloader ActiveX
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IE 7.0.5730.11 (WinXP SP2), IE 6.0.2900.2180 (WinXP SP2)
2006
Rediff Bol Downloader ActiveX Allows Downloading and Spawning Arbitary Files
Rediff Bol Downloader ActiveX control allows any webpage to download and spawn file. These file can be of any type. No filtering is done. IE Displays an alert, if the code points to a executable file on the internet. But execution of local files displays no alert.
Mitigation:
N/A