OSVDB ID: 27049

Title: iMBCContents ActiveX Control Execute() Method Arbitrary Program Execution

Info

Disclosure

Jul 05, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

iMBCContents contains a flaw that may allow a malicious user to execute code remotely. The issue is triggered when an attacker executes arbitrary program on the target via a URI using the 'file:' URI handler. This could allow an attacker to create a specially crafted web page that would execute arbitrary code in the context of the user visiting a malicious web page resulting in a loss of integrity.

Classification

Location: Remote / Network Access, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity

Solution

Upgrade to version 2.0.0.59 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Muhwa Broadcasting Corp.

iMBCContents

2.0.0.55

References

Credit

  • Gyu Tae Park -


Direct URL: http://osvdb.org/27049