8.8
CVSSv2

CVE-2009-0865

Published: 10/03/2009 Updated: 19/10/2017
CVSS v2 Base Score: 8.8 | Impact Score: 9.2 | Exploitability Score: 8.6
VMScore: 885
Vector: AV:N/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote malicious users to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods.

Vulnerable Product Search on Vulmon Subscribe to Product

geovision livex activex control 8.1.2.0

geovision livex activex control 8.2.0.0

Exploits

<!-- GeoVision LiveX_v8200 ActiveX Control (LIVEX_~1OCX) remote file corruption poc by Nine:Situations:Group::SnoopyAssault site: retrogodaltervistaorg/ working against IE8b/xpsp3, safe for scripting and for initialize LiveX_v7000 with clsid {DA8484DE-52DB-4860-A986-61A8682E298A} LiveX_v8120 with clsid {F4421170-DB22-4551-BBFB-FFCFFB ...