Hole in Clever Internet ActiveX Suite control
The WebDAV control (clinetsuitex6.ocx) of the Clever Internet ActiveX Suite, contains a critical vulnerability that allows web pages to overwrite arbitrary files on a PC running the control. The control also allows attackers to load and store files in arbitrary locations.
These bugs in the WebDAV control, which supports collaborative editing and management of files, allow an attacker to store his own programs on the system and execute them, for instance via the autostart folder when the system is restarted. The cause of this problem is not a bug, but rather a design decision. The control is marked as "safe for scripting", although it grants full access to the file system to any web page. This flaw affects version 6.2 of the suite. An update has not been provided; the only workaround is to set the kill bit.
- Clever Internet ActiveX Suite 6.2 "GetToFile" Arbitrary file download/overwrite Exploit, security advisory by shinnai
(mba)