The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."
Software | From | Fixed in |
---|---|---|
icona / instant_messenger | 1.0.0.1 | 1.0.0.1.x |