CVE-2008-1725
9.0
Vector
AV:N/AC:M/Au:N/C:P/I:C/A:C
Exploitability: 8.6 / Impact: 9.5
Source: NVD
Description
The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname in the argument. NOTE: some of these details are obtained from third party information.
Affected (1)
Products: Nsoftware: Ibiz E Banking Integrator
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.0.2932 |
References (10)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.