Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-5897

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implement the SaveToFile method, which allows remote attackers to write or overwrite arbitrary files via the bstrFileName argument.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.107
EPSS Ranking 93.0%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2012-5897
  • Quest » Intrust » Version: 10.1
    cpe:2.3:a:quest:intrust:10.1
  • Quest » Intrust » Version: 10.2.5
    cpe:2.3:a:quest:intrust:10.2.5
  • Quest » Intrust » Version: 10.3
    cpe:2.3:a:quest:intrust:10.3
  • Quest » Intrust » Version: 10.4
    cpe:2.3:a:quest:intrust:10.4
  • Quest » Intrust » Version: 10.4.0.853
    cpe:2.3:a:quest:intrust:10.4.0.853


Contact Us

Shodan ® - All rights reserved