Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first parameter to the DonwloadAndInstall method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Sina DLoader Class ActiveX控件安全漏洞
Vulnerability Description
Sina DLoader Class ActiveX控件是新浪客户端得一个控件。 新浪UC客户端所安装的DLoader Class ActiveX控件(默认安装路径%Windir%Downloaded Program FilesDownloader.DLL)没有正确地验证对DonwloadAndInstall方式的输入,如果用户受骗访问了恶意网页并向该方式传送了畸形参数的话,就会导致向用户系统的任意位置下载文件。目前已有蜜罐网络检测到该漏洞正在被积极的利用。
CVSS Information
N/A
Vulnerability Type
N/A