|
SigPlus Pro ActiveX contains a flaw related to the unsafe "SetLogFilePath()" method in combination with e.g. the "SigMessage()" method. The issue is triggered when a remote attacker tricks a user into viewing a specially crafted web page instantiating the ActiveX. This may allow an attacker to create an arbitrary file with controlled content on the user's system.
|