HTTP: ADODB.Connection File Installation Weakness

This signature detects attempts to exploit a known vulnerability in the ADODB.Connection ActiveX Object of Microsoft Internet Explorer (IE). IE 6.0 and earlier are vulnerable. Attackers can trick users into downloading a malicious VBScript and executing the script locally. A successful attack can enable attackers to overwrite a file on the local host.

Extended Description

Successful exploitation enables an attacker to install Trojan horses or backdoor programs on the local filesystem, including the Startup folder, which could lead to complete compromise of the target host.

Short Name
HTTP:STC:ACTIVEX:ADODB-CONNECT
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
ADODB.Connection File Installation Weakness
Release Date
03/16/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?