Vulnerability Name: | CVE-2004-1947 (CCN-15911) | ||||||||
Assigned: | 2004-04-19 | ||||||||
Published: | 2004-04-19 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | The AVXSCANONLINE.AvxScanOnlineCtrl.1 ActiveX control in BitDefender Scan Online allows remote attackers to (1) obtain sensitive information such as system drives and contents or (2) use the RequestFile method to download and execute arbitrary code via an object codebase that uses bitdefender.cab. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Apr 20 2004 - 04:39:38 CDT Re: [Full-Disclosure] BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure Source: MITRE Type: CNA CVE-2004-1947 Source: BUGTRAQ Type: UNKNOWN 20040419 BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure Source: BUGTRAQ Type: UNKNOWN 20040420 Re: BitDefender Scan Online(ActiveX) - Remote File Download & Execute & Private Information Disclosure Source: CCN Type: SA11427 AvxScanOnline ActiveX Control Arbitrary File Execution Vulnerability Source: SECUNIA Type: Exploit, Vendor Advisory 11427 Source: CCN Type: SECTRACK ID: 1009862 BitDefender Scan Online ActiveX Control Lets Remote Users Install and Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1009862 Source: OSVDB Type: UNKNOWN 5549 Source: CCN Type: OSVDB ID: 5549 BitDefender AvxScanOnline ActiveX Control Arbitrary File Execution Source: BID Type: UNKNOWN 10174 Source: CCN Type: BID-10174 Softwin BitDefender AvxScanOnlineCtrl COM Object Remote File Upload And Execution Vulnerability Source: BID Type: Exploit, Patch, Vendor Advisory 10175 Source: CCN Type: BID-10175 Softwin BitDefender AvxScanOnlineCtrl COM Object Information Disclosure Vulnerability Source: XF Type: UNKNOWN bitdefender-avxscanonline-code-execution(15911) Source: XF Type: UNKNOWN bitdefender-avxscanonline-code-execution(15911) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |