Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-6127

Опубликовано: 25 окт. 2013
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the two pathname arguments, as demonstrated by a directory traversal attack.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:wellintech:kingview:*:*:*:*:*:*:*:*
Версия до 6.53 (включая)
cpe:2.3:a:wellintech:kingview:3.0:*:*:*:*:*:*:*
cpe:2.3:a:wellintech:kingview:6.52:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.04222
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the two pathname arguments, as demonstrated by a directory traversal attack.

EPSS

Процентиль: 88%
0.04222
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-22