|
JaguarEditControl ActiveX Control Information Disclosure
|
|
Secunia Advisory:
|
SA20759
|
|
|
Release Date:
|
2006-06-22
|
|
Last Update:
|
2006-06-28
|
|
Popularity:
|
5,040 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Exposure of system information
|
|
Where:
|
From remote
|
|
Solution Status:
|
Unpatched
|
|
| Software: | JaguarEditControl
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
| | CVE reference: | CVE-2006-3217
|
|
Description: SRLabs.net has discovered a security issue in JaguarEditControl, which can be exploited by malicious people to disclose certain system information.
The problem is caused due to the ActiveX control disclosing certain information of the user's system via the JText attribute when the "test" parameter is set to 2790 or 2404. This can be exploited to disclose the user's Windows username, system name, MAC address, IP address, and gateway IP address.
Successful exploitation requires that e.g. the user is tricked into visiting a malicious website.
The security issue has been confirmed in version 1,1,0,18 (DEMO) and has also been reported in version 1,1,0,19 and 1,1,0,20. Other versions may also be affected.
Solution: Do not visit non-trusted website.
Provided and/or discovered by: SRLabs.net
Changelog: 2006-06-28: Added CVE reference.
Original Advisory: http://www.srlabs.net/bulten/JaguarEdit_2.htm
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
7th Jan, 2009
|
New advisories:
|
31 |
|
New vulnerabilities:
|
90 |
|
Updated advisories:
|
37 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|