In association with heise online

27 July 2007, 15:04

Hole in Clever Internet ActiveX Suite control

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

The WebDAV control (clinetsuitex6.ocx) of the Clever Internet ActiveX Suite, contains a critical vulnerability that allows web pages to overwrite arbitrary files on a PC running the control. The control also allows attackers to load and store files in arbitrary locations.

These bugs in the WebDAV control, which supports collaborative editing and management of files, allow an attacker to store his own programs on the system and execute them, for instance via the autostart folder when the system is restarted. The cause of this problem is not a bug, but rather a design decision. The control is marked as "safe for scripting", although it grants full access to the file system to any web page. This flaw affects version 6.2 of the suite. An update has not been provided; the only workaround is to set the kill bit.

See also:


Print Version | Send by email | Permalink:

  • July's Community Calendar

The H Open

The H Security

The H Developer

The H Internet Toolkit