The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in...
Vulnerability Description
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-3879
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.exploit-db.com/exploits/6319
- http://securityreason.com/securityalert/4201
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44750
- http://secunia.com/advisories/31632
- http://www.shinnai.net/xplits/TXT_NPku7jFjRufaz85U6Lxn.html
- http://www.shinnai.net/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1219827906.ff.php
- http://www.securityfocus.com/bid/30863
Affected Vendor
ultrashareware
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.