9.3
CVSSv2

CVE-2008-0221

Published: 10/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote malicious users to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

gateway weblaunch 1.0.0.1

Exploits

<!-- Gateway Weblaunch ActiveX Control Insecure Method Exploit Implemented Categories: Category: Safe for Initialising Category: Safe for Scripting Written by eb Tested on Windows XP SP2(fully patched) English, IE6, weblaunchocx version 1001 This method is also vulnerable to a buffer overflow in the 2nd and 4th parameters --> <html& ...