Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Synactis Subscribe
Filtered by product All In The Box.ocx
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-0465 1 Synactis 1 All In The Box.ocx 2017-09-28 9.3 HIGH N/A
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0' character, which bypasses the intended .box filename extension, as demonstrated by a C:\boot.ini\0 argument.