5.8
CVSSv2

CVE-2013-6128

Published: 25/10/2013 Updated: 28/10/2013
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx prior to 65.30.30000.10002 in WellinTech KingView prior to 6.53 does not properly restrict SaveToFile method calls, which allows remote malicious users to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the single pathname argument, as demonstrated by a directory traversal attack.

Vulnerable Product Search on Vulmon Subscribe to Product

wellintech kingview

Exploits

<!-- KingView ActiveX Control (KChartXY) Remote File Creation / Overwrite Vendor: wwwwellintechcom Version: KingView 653 Tested on: Windows XP SP3 / IE Download: wwwwellintechcom/documents/KingView653_ENzip Author: Blake CLSID: A9A2011A-1E02-4242-AAE0-B239A6F88BAC ProgId: KCHARTXYLibKChartXY Path: C:\Program Files\KingVie ...