The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary files on the host machine by uploading a file with an extension that is not associated with an application, and selecting a file from the "Open With..." dialog.
Link | Tags |
---|---|
http://securitytracker.com/id?1016124 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26711 | vdb entry |
http://secunia.com/advisories/20165 | third party advisory |
http://www.securityfocus.com/archive/1/434400/100/0/threaded | mailing list |