Back to search
CVE-2012-5897
Published: Nov 17, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
52773
vdb-entry
x_refsource_BID
18672
exploit
x_refsource_EXPLOIT-DB
80664
vdb-entry
x_refsource_OSVDB
intrust-ardoc-file-overwrite(74442)
vdb-entry
x_refsource_XF
48566
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now