CVE-2010-2584
The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the…
Does this matter?
Lower severity and a low EPSS score (1.40%). Track it; it rarely justifies an emergency change on its own.
Description
The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL property.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.40% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- realpage/module activex controls
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/41392Vendor Advisory
- http://secunia.com/secunia_research/2010-118/Vendor Advisory
- http://www.osvdb.org/68813
- http://www.securityfocus.com/bid/44302
- http://secunia.com/advisories/41392Vendor Advisory
- http://secunia.com/secunia_research/2010-118/Vendor Advisory
- http://www.osvdb.org/68813
- http://www.securityfocus.com/bid/44302
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.