CVE Vulnerabilities

CVE-2012-5897

Published: Nov 17, 2012 | Modified: Sep 02, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.

Affected Software

Name Vendor Start Version End Version
Intrust Quest * 10.4.0.853 (including)
Intrust Quest 10.1 (including) 10.1 (including)
Intrust Quest 10.2.5 (including) 10.2.5 (including)
Intrust Quest 10.3 (including) 10.3 (including)
Intrust Quest 10.4 (including) 10.4 (including)

References