CVE Database
/

CVE-2012-5897

Back to search

CVE-2012-5897

Published: Nov 17, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

VendorProductVersions

n/a

n/a

affected
n/a

References

52773
vdb-entry
x_refsource_BID
18672
exploit
x_refsource_EXPLOIT-DB
80664
vdb-entry
x_refsource_OSVDB
48566
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now