CVE-2013-6127
medium · 5.8The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the two pathname arguments, as demonstrated by a directory traversal attack.
5.8
CVSS
13.9%
EPSS (exploit prob.)
96th
EPSS percentile
2013-10-25
Published
AV:N/AC:M/Au:N/C:N/I:P/A:P
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wellintech | kingview | <= 6.53 |
| wellintech | kingview | 3.0 |
| wellintech | kingview | 6.52 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-6127