Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the two pathname arguments, as demonstrated by a directory traversal attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WellinTech KingView ActiveX 多个任意文件覆盖漏洞
Vulnerability Description
Kingview(组态王)是中国亚控(WellinTech)公司的一套工业组态软件。该软件包含了一个稳定的采集架构,并提供导入导出设备变量、向导式报表、Web发布等功能。 WellinTech KingView 6.53之前的版本中的SuperGrid.ocx控件65.30.30000.10002之前的版本中的SUPERGRIDLib.SuperGrid ActiveX控件模块中存在安全漏洞,该漏洞源于程序没有正确限制ReplaceDBFile方法的调用。远程攻击者可借助‘two pathname’参数利
CVSS Information
N/A
Vulnerability Type
N/A