The (1) SetDebugging and (2) RunEgatherer methods in IBM Access Support eGatherer ActiveX control 2.0.0.16 allow remote attackers to create files with arbitrary content, as demonstrated by creating a .hta file in a Startup folder.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Egatherer | Ibm | 2.0.0.16 (including) | 2.0.0.16 (including) |