This application requires Javascript for optimal performance.

Data.Dynamics.ActiveBar.Actbar3.OCX.ActiveX.Insecure.Method

Release Date

Jan 05, 2012

Severity

medium

Impact

Security Bypass: Remote attackers can bypass security checking of vulnerable systems.

Description

This indicates an attack attempt against a Security Bypass vulnerability in the Data Dynamics ActiveBar ActiveX control (actbar3.ocx).

The vulnerability is caused by an error when the vulnerable ActiveX control handles a specially crafted full path name. It allows a remote attacker to create or overwrite files.

Affected Products

Data Dynamics ActiveBar ActiveX Control 3.2
Data Dynamics ActiveBar ActiveX Control 3.1

Recommended Actions

Update to the latest versions:

http://www.datadynamics.com/Products/ProductOverview.aspx?Product=AB

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-3883

Reference/s

http://www.securityfocus.com/bid/24959 (BugTraq)

Reference: VID-30501