CVE-2011-5290: Medium severity idrive online backup vulnerability
Published Jan 1, 2015
·Updated
The SaveToFile method in the UniBasicPack.UniTextBox ActiveX control in UniBasic100EDA1811C.ocx in IDrive Online Backup 3.4.0 allows remote attackers to write to arbitrary files via a pathname in the first argument.
Affected Software
1 affected component
Idrive Inc Idrive Online Backup=3.4.0
Event History
Jan 1, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-5290?
CVE-2011-5290 is classified as a high-severity vulnerability due to its ability to allow remote file writing.
2
How do I fix CVE-2011-5290?
To mitigate CVE-2011-5290, users should update to a patched version of IDrive Online Backup or disable the affected ActiveX control.
3
What type of attacks can exploit CVE-2011-5290?
CVE-2011-5290 can be exploited by remote attackers to conduct unauthorized file writing attacks.
4
Which software versions are affected by CVE-2011-5290?
CVE-2011-5290 specifically affects IDrive Online Backup version 3.4.0.
5
Is there any known exploit for CVE-2011-5290?
Yes, there are known exploits that leverage the SaveToFile method in the UniBasicPack.UniTextBox ActiveX control.