Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-0501

Опубликовано: 12 апр. 2013
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:cognos_disclosure_management:10.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00774
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.

EPSS

Процентиль: 73%
0.00774
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-264