9.3
CVSSv2

CVE-2012-5897

Published: 17/11/2012 Updated: 02/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and previous versions do not properly implement the SaveToFile method, which allows remote malicious users to write or overwrite arbitrary files via the bstrFileName argument.

Vulnerable Product Search on Vulmon Subscribe to Product

quest intrust 10.1

quest intrust

quest intrust 10.4

quest intrust 10.3

quest intrust 10.2.5

Exploits

Quest InTrust 104x ReportTree and SimpleTree Classes ArDocdll ActiveX Control Remote File Creation / Overwrite homepage: wwwquestcom/intrust/ description: "InTrust securely collects, stores, reports and alerts on event log data from Windows, Unix and Linux systems, helping you comply with external regulations, internal policies and ...