Vulnerabilities > CVE-2007-3883 - Insecure Methods vulnerability in Data Dynamics ActiveBar Actbar3.OCX ActiveX Control

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
datadynamics
nessus
exploit available

Summary

The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in (1) the second argument to the Save method, or the first argument to the (2) SaveLayoutChanges or (3) SaveMenuUsageData method.

Vulnerable Configurations

Part Description Count
Application
Datadynamics
3

Exploit-Db

  • descriptionData Dynamics ActiveBar ActiveX (actbar3.ocx <= 3.1) Insecure Methods. CVE-2007-3883. Remote exploit for windows platform
    fileexploits/windows/remote/4190.html
    idEDB-ID:4190
    last seen2016-01-31
    modified2007-07-17
    platformwindows
    port
    published2007-07-17
    reportershinnai
    sourcehttps://www.exploit-db.com/download/4190/
    titleData Dynamics ActiveBar ActiveX actbar3.ocx <= 3.1 Insecure Methods
    typeremote
  • idEDB-ID:5395

Nessus

NASL familyWindows
NASL idDATA_DYNAMICS_ACTIVEBAR_ACTIVEX.NASL
descriptionOne or more of the Data Dynamics ActiveBar ActiveX controls installed on the remote Windows host is affected by a code execution vulnerability due to unspecified issues in the
last seen2020-06-01
modified2020-06-02
plugin id54841
published2011-05-27
reporterThis script is Copyright (C) 2011-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/54841
titleData Dynamics ActiveBar ActiveX Controls Code Execution