The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2008/1733/references | vdb entry |
http://securityreason.com/securityalert/3926 | third party advisory |
http://secunia.com/advisories/30512 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/29519 | vdb entry |
http://www.securityfocus.com/archive/1/493019/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42825 | vdb entry |
https://www.exploit-db.com/exploits/5732 | exploit |