Synactis All In-The-Box ActiveX 3.1

Set the kill-bit for the affected ActiveX control
Rating
Your vote:
Latest version:
4.03 See all
Developer:
Secunia ApS
Screenshots
1 / 1
Download

A vulnerability has been discovered in the Synactis ALL In-The-Box ActiveX control, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to the All_In_The_Box.AllBox ActiveX control (All_In_The_Box.ocx) providing the insecure "SaveDoc()" method. This can be exploited to overwrite arbitrary files on the system via a filename terminated by a NULL byte.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in All_In_The_Box.ocx version 3.1.2.0. Other versions may also be affected.

Comments

User

Your vote:

Related software

AddEmail ActiveX
AddEmail ActiveX
rating

It allows you to create text or HTML email messages with attachments.

Purple Parrot NumberBox ActiveX
Purple Parrot NumberBox ActiveX
rating

It is a data-aware control which enhances the standard text box.

Active MP3 DJ Studio
Active MP3 DJ Studio
rating

Adds sound playback and mixing capabilities to applications.

AzSDK PDF Decrypt ActiveX DLL
AzSDK PDF Decrypt ActiveX DLL
rating

Decrypt and encrypt PDFs in your Win programs or Web applications.

Magic CD/DVD Burner ActiveX
Magic CD/DVD Burner ActiveX
rating

It is an ActiveX based data CD/DVD writing solution for developers.