Liquid XML studio ActiveX openfile BO

Strike ID:
E10-6j201
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
t
Variants:
2
Year:
2010

Description

This strike exploits buffer overflow vulnerability within a Liquid XML studio ActiveX. This vulnerability is due to lack of confirmation of filename length when handling the openfile function. Remote unauthenticated attackers could exploit this vulnerability to execute arbitrary code on the target system

References