Vulnerability CVE-2008-1725


Published: 2008-04-11   Modified: 2012-02-12

Description:
The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname in the argument. NOTE: some of these details are obtained from third party information.

Type:

CWE-DesignError

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9/10
9.5/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Complete
Complete
Affected software
Nsoftware -> Ibiz e-banking integrator 

 References:
http://xforce.iss.net/xforce/xfdb/41752
http://www.securityfocus.com/bid/28700
http://www.osvdb.org/44393
http://www.milw0rm.com/exploits/5416
http://secunia.com/advisories/29758

Copyright 2024, cxsecurity.com

 

Back to Top