Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.900489
Categoría:Windows
Título:Orbit Downloader File Deletion ActiveX Vulnerability
Resumen:This host is installed with Orbit Downloader and is prone to; File Deletion ActiveX Vulnerability.
Descripción:Summary:
This host is installed with Orbit Downloader and is prone to
File Deletion ActiveX Vulnerability.

Vulnerability Insight:
Bug in the 'download()' function method which lets the attacker to delete
arbitrary files in the victim's computer.

Vulnerability Impact:
Successful exploitation will let the attacker execute arbitrary codes in a
crafted webpage and trick the victim to visit the malicious link which lets
the attacker execute the vulnerable code into the context of the affected remote system.

Affected Software/OS:
Orbit Downloader 'Orbitmxt.dll' version 2.1.0.2 and prior.

Solution:
Upgrade to Orbit Downloader Version 3.0 or later.

Workaround:
Set the Killbit for the vulnerable CLSID {3F1D494B-0CEF-4468-96C9-386E2E4DEC90}

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:P

Referencia Cruzada: BugTraq ID: 34200
Common Vulnerability Exposure (CVE) ID: CVE-2009-1064
http://www.securityfocus.com/bid/34200
https://www.exploit-db.com/exploits/8257
http://www.waraxe.us/advisory-73.html
XForce ISS Database: orbitdownloader-activex-file-deletion(49353)
https://exchange.xforce.ibmcloud.com/vulnerabilities/49353
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.