Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6pr-3gfh-7g78

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.

The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.

EPSS

Процентиль: 94%
0.12164
Средний

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 17 лет назад

The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.

EPSS

Процентиль: 94%
0.12164
Средний

Дефекты

CWE-20