Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:ACTIVEX:REDIFFBOL

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Rediff Bol Downloader Unsafe ActiveX Control Remote Code Execution

Release Date

2012/12/02

Update Number

2207

Supported Platforms

idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Rediff Bol Downloader Unsafe ActiveX Control Remote Code Execution


This signature detects attempts to use unsafe ActiveX controls against Rediff Bol Downloader. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

Rediff Bol Downloader ActiveX control is prone to a remote code-execution vulnerability. Exploiting this issue allows remote attackers to download and execute arbitrary code in the context of applications using the affected ActiveX control and possibly to compromise affected computers.

Affected Products

  • Rediff Bol Downloader ActiveX control

References

  • BugTraq: 21831
  • CVE: CVE-2006-6838

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out