Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-5021

Опубликовано: 06 авг. 2013
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager 1 through 6.3.6, and other products allow remote attackers to create and execute arbitrary files via a full pathname in an argument to the ExportStyle method in the (1) CWNumEdit, (2) CWGraph, (3) CWBoolean, (4) CWSlide, or (5) CWKnob ActiveX control, in conjunction with file content in the (a) Caption or (b) FormatString property value.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ni:labview:*:*:*:*:*:*:*:*
Версия до 2012 (включая)
cpe:2.3:a:ni:labwindows:*:*:*:*:*:*:*:*
Версия до 2012 (включая)
cpe:2.3:a:ni:measurementstudio:*:*:*:*:*:*:*:*
Версия до 2013 (включая)
cpe:2.3:a:ni:teststand:*:*:*:*:*:*:*:*
Версия до 2012 (включая)
Конфигурация 2

Одно из

cpe:2.3:a:abb:datamanager:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:abb:datamanager:6.3.6:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00739
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager 1 through 6.3.6, and other products allow remote attackers to create and execute arbitrary files via a full pathname in an argument to the ExportStyle method in the (1) CWNumEdit, (2) CWGraph, (3) CWBoolean, (4) CWSlide, or (5) CWKnob ActiveX control, in conjunction with file content in the (a) Caption or (b) FormatString property value.

EPSS

Процентиль: 72%
0.00739
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-22