9.3
CVSSv2

CVE-2008-2511

Published: 02/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote malicious users to create and overwrite arbitrary files via a .. (dot dot) in the argument to the SaveToFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

ca internet security suite plus 2008

Exploits

<!-- CA Internet Security Suite 2008 (UmxEventClidll/SaveToFile()) remote file corruption poc by Nine:Situations:Group::surfista this control is safe for scripting and safe for initialize original one: retrogodaltervistaorg/9sg_CA_pochtml --> <html><object classid='clsid:F13D3742-6C4F-4915-BF91-784BA02DD0BE' id='UmxEvent ...