CVE Vulnerabilities

CVE-2011-5291

Published: Jan 01, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The SaveData method in the Cygnicon.ViewControl.1 ActiveX control in CyViewer.ocx in Ashampoo 3D CAD Professional 3.x before 3.0.2 allows remote attackers to write to arbitrary files via a pathname in the first argument.

Affected Software

NameVendorStart VersionEnd Version
Ashampoo_3d_cad_professional_3Ashampoo_gmbh_&_co.3.0 (including)3.0 (including)
Ashampoo_3d_cad_professional_3Ashampoo_gmbh_&_co.3.0.1 (including)3.0.1 (including)

References