Описание
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ibm:cognos_disclosure_management:10.2.0:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00774
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
почти 4 года назад
The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM) 10.2.0, and other products, allows remote attackers to read arbitrary files, or download an arbitrary program onto a client machine and execute this program, via a crafted web site.
EPSS
Процентиль: 73%
0.00774
Низкий
9.3 Critical
CVSS2
Дефекты
CWE-264