CVE-2004-2663

IBM Access Support eGatherer ActiveX control 2.0.0.16 - Code Injection

Title source: llm
STIX 2.1

Description

The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.

References (8)

Core 8
Core References
Various Sources third-party-advisory x_refsource_eeye
http://research.eeye.com/html/advisories/published/AD20040615B.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16428
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.eeye.com/html/research/advisories/AD20040615B.html
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108746693619324&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11072
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=108741557604568&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/7090
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10562

Scores

EPSS 0.0195
EPSS Percentile 78.1%

Details

Status published
Products (1)
ibm/egatherer 2.0.0.16
Published Dec 31, 2004
Tracked Since Feb 18, 2026