First published: Thu Jan 01 2015(Updated: )
The SaveMessage method in the LEADeMail.LEADSmtp.20 ActiveX control in LTCML14n.dll 14.0.0.34 in Kofax e-Transactions Sender Sendbox 2.5.0.933 allows remote attackers to write to arbitrary files via a pathname in the first argument.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kofax Kofax E-transactions Sender Sendbox | =2.5.0.933 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5294 has a medium severity rating due to its potential for remote code execution.
To fix CVE-2011-5294, update Kofax e-Transactions Sender Sendbox to a version that patches this vulnerability.
CVE-2011-5294 allows remote attackers to write to arbitrary files which could lead to data breaches or system compromise.
CVE-2011-5294 affects Kofax e-Transactions Sender Sendbox version 2.5.0.933.
There have been reports of CVE-2011-5294 being exploited in the wild, making it critical to apply patches.