CVE-2008-1725

IBiz E-Banking Integrator <2.0.2932 - Code Injection

Title source: llm

Description

The IBizEBank.FIProfile.1 ActiveX control in fiprofile20.ocx in IBiz E-Banking Integrator (formerly IBiz OFX Integrator) 2.0.2932 exposes the unsafe WriteOFXDataFile method, which allows remote attackers to overwrite arbitrary files via a full pathname in the argument. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/5416

Scores

EPSS 0.0502
EPSS Percentile 89.8%

Details

Status published
Products (1)
nsoftware/ibiz_e-banking_integrator 2.0.2932
Published Apr 11, 2008
Tracked Since Feb 18, 2026