First published: Tue Mar 10 2009(Updated: )
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Geovision Livex Activex Control | =8.1.2.0 | |
Geovision Livex Activex Control | =8.2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-0865 is rated high with a score of 8.8.
To fix CVE-2009-0865, update the GeoVision LiveX ActiveX control to a safe version not vulnerable to directory traversal.
CVE-2009-0865 is a directory traversal vulnerability in the SnapShotToFile method that allows attackers to create or overwrite arbitrary files.
CVE-2009-0865 affects GeoVision LiveX ActiveX control versions 8.1.2.0 and 8.2.0.0.
CVE-2009-0865 can be exploited remotely by manipulating the SnapShotToFile method's arguments to include .. (dot dot) sequences.