CVE-2009-0865
GeoVision LiveX ActiveX Control 8.1.2 and 8.2.0 - Path Traversal via SnapShotToFile Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0865. PoCs published by Nine:Situations:Group.
AI-analyzed exploit summary This exploit targets a file corruption vulnerability in GeoVision LiveX ActiveX Control (LIVEX_~1.OCX) by abusing the SnapShotToFile() method to overwrite system.ini with JPEG content. It demonstrates arbitrary file write via directory traversal.
Description
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods.
Exploits (1)
This exploit targets a file corruption vulnerability in GeoVision LiveX ActiveX Control (LIVEX_~1.OCX) by abusing the SnapShotToFile() method to overwrite system.ini with JPEG content. It demonstrates arbitrary file write via directory traversal.