2089Third-party advisory
http://securityreason.com/securityalert/2089 CVE-2006-6838
Rediff Bol Downloader - ActiveX Control Execute Local File
Record summary
CVE-2006-6838 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Rediff Bol Downloader ActiveX (OCX) control allows remote attackers to execute arbitrary files, and obtain sensitive information (usernames and pathnames), via a URL in the url vbscript parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRediff Bol Downloader - ActiveX Control Execute Local FileExploitDB exploitby Gregory R. PanakkalNot analyzed1 file
References
5infogreg.com
http://www.infogreg.com/security/misc/rediff-bol-downloader-allows-downloading-and-spawning-arbitary-files.html 20061231 Rediff Bol Downloader Allows Downloading and Spawning Arbitary Filesmailing list
http://www.securityfocus.com/archive/1/455611/100/0/threaded 21831vdb entry
http://www.securityfocus.com/bid/21831 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-6838