Vulnerabilities > CVE-2009-0389 - Unspecified vulnerability in Eztools-Software web ON Windows Activex 2

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
eztools-software
critical
exploit available

Summary

Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and (4) write to the registry via unspecified vectors. NOTE: vectors 1 and 2 can be used together to execute arbitrary code.

Vulnerable Configurations

Part Description Count
Application
Eztools-Software
1

Exploit-Db

descriptionWOW - Web On Windows ActiveX Control 2 Remote Code Execution. CVE-2009-0389. Remote exploit for windows platform
fileexploits/windows/remote/7910.html
idEDB-ID:7910
last seen2016-02-01
modified2009-01-29
platformwindows
port
published2009-01-29
reporterMichael Brooks
sourcehttps://www.exploit-db.com/download/7910/
titleWOW - Web On Windows ActiveX Control 2 - Remote Code Execution
typeremote