6.3
CVSSv2

CVE-2011-5155

Published: 06/09/2012 Updated: 06/09/2012
CVSS v2 Base Score: 6.3 | Impact Score: 9.2 | Exploitability Score: 3.4
VMScore: 635
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:N

Vulnerability Summary

Untrusted search path vulnerability in Help & Manual 5.5.1 Build 1296 allows local users to gain privileges via a Trojan horse ijl15.dll file in the current working directory, as demonstrated by a directory that contains a .hmxz, .hmxp, .hmskin, .hmx, .hm3, .hpj, .hlp, or .chm file. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

helpandmanual help \\& manual 5.5.1

Exploits

source: wwwsecurityfocuscom/bid/47349/info EC Software Help & Manual is prone to an arbitrary-code-execution vulnerability An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file ...