Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveToFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the single pathname argument, as demonstrated by a directory traversal attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WellinTech KingView ActiveX 控件不安全方法漏洞
Vulnerability Description
Kingview(组态王)是中国亚控(WellinTech)公司的一套工业组态软件。该软件包含了一个稳定的采集架构,并提供导入导出设备变量、向导式报表、Web发布等功能。 WellinTech KingView 6.53之前的版本中的KChartXY.ocx控件65.30.30000.10002之前的版本中的KCHARTXYLib.KChartXY ActiveX控件模块中存在安全漏洞,该漏洞源于程序没有正确限制SaveToFile方法的调用。远程攻击者可借助‘single pathname’参数利用该漏
CVSS Information
N/A
Vulnerability Type
N/A