Vulnerabilities > CVE-2009-0134 - Arbitrary File Overwrite vulnerability in Share2 Easy Grid Control 3.51

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
share2
critical
exploit available

Summary

Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Share2
1

Exploit-Db

descriptionAAA EasyGrid ActiveX 3.51 Remote File Overwrite Exploit. CVE-2009-0134. Remote exploit for windows platform
fileexploits/windows/remote/7779.html
idEDB-ID:7779
last seen2016-02-01
modified2009-01-14
platformwindows
port
published2009-01-14
reporterHoussamix
sourcehttps://www.exploit-db.com/download/7779/
titleAAA EasyGrid ActiveX 3.51 - Remote File Overwrite Exploit
typeremote