PT-2008-5214 · Ultra · Ultra Office Control
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ultra Office Control version 2.0.2008.801 and earlier
Description
The issue allows remote attackers to force the download of arbitrary files onto a client system. This is achieved by using a URL in the first argument to the
Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.Recommendations
For Ultra Office Control version 2.0.2008.801 and earlier, consider disabling the
Open and Save methods until a patch is available to prevent the forced download of arbitrary files. Restrict access to the Ultra.OfficeControl ActiveX control to minimize the risk of exploitation.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ultra Office Control