Check Point Reference: | CPAI-2012-035 |
Date Published: | 19 Mar 2012 |
Severity: | Medium |
Last Updated: | Sunday 16 February, 2025 |
Source: | |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | Bennet-Tec TList 6 Bennet-Tec TList 7 Bennet-Tec TList 8 |
Vulnerability Description | An arbitrary file creation vulnerability has been reported in Bennet-Tec TList's ActiveX control. |
Vulnerability Details | The vulnerability is due to a directory traversal in the ActiveX control while handling a certain method. A remote attacker may exploit this vulnerability by enticing a target user to open a specially crafted web page. Successful exploitation could allow an attacker to create or rewrite arbitrary files in the context of the currently logged-on user. |
This protection will detect and block attempts to open a malicious web page.
In order for the protection to be activated, update your product to the latest update. For information on how to update , go to SBP-2006-05, Protection tab and select the version of your choice.
SmartView Tracker will log the following entries:
Attack Name: Web Client Enforcement Violation
Attack Information: Bennet-Tec TList ActiveX SaveData arbitrary file creation