Vulnerabilities > CVE-2008-1725 - Insecure Method vulnerability in Nsoftware Ibiz E-Banking Integrator 2.0.2932

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
nsoftware
critical
exploit available

Summary

The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname in the argument. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Nsoftware
1

Exploit-Db

descriptionIBiz E-Banking Integrator V2 ActiveX Edition Insecure Method Exploit. CVE-2008-1725. Remote exploit for windows platform
fileexploits/windows/remote/5416.html
idEDB-ID:5416
last seen2016-01-31
modified2008-04-09
platformwindows
port
published2008-04-09
reportershinnai
sourcehttps://www.exploit-db.com/download/5416/
titleIBiz E-Banking Integrator 2.0 - ActiveX Edition Insecure Method Exploit
typeremote