Vulnerabilities > CVE-2008-4923 - Arbitrary File Overwrite vulnerability in MW6 Technologies Aztec Activex 3.0.0.1

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
mw6-technologies
critical
exploit available

Summary

Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

Vulnerable Configurations

Part Description Count
Application
Mw6_Technologies
1

Exploit-Db

descriptionMW6 Aztec ActiveX (Aztec.dll) Remote Insecure Method Exploit. CVE-2008-4923. Remote exploit for windows platform
fileexploits/windows/remote/6870.html
idEDB-ID:6870
last seen2016-02-01
modified2008-10-29
platformwindows
port
published2008-10-29
reporterDeltahackingTEAM
sourcehttps://www.exploit-db.com/download/6870/
titleMW6 Aztec ActiveX Aztec.dll Remote Insecure Method Exploit
typeremote