vendor:
TVUPlayer
by:
Unknown
5.5
CVSS
MEDIUM
Arbitrary File Overwrite
Unknown
CWE
Product Name: TVUPlayer
Affected Version From: TVUPlayer 2.4.9beta1 [build1797]
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
TVUPlayer ActiveX control arbitrary file overwrite vulnerability
The TVUPlayer ActiveX control in TVUPlayer 2.4.9beta1 allows attackers to overwrite arbitrary local files on the victim's computer through a crafted XML package. This vulnerability can be exploited in the context of the vulnerable application, typically Internet Explorer, using the ActiveX control.
Mitigation:
Unknown