CVE-2009-0465 describes a critical vulnerability in the Synactis ALL In-The-Box ActiveX control (ALL_IN_THE_BOX.OCX version 3). This flaw allows remote attackers to create or overwrite arbitrary files on a vulnerable system by exploiting the SaveDoc method. Attackers can bypass the intended .box filename extension by appending a null byte ('\0') to the filename argument, as demonstrated by overwriting critical system files like C:\boot.ini. The vulnerability carries a CVSS score of 9.3, indicating severe impact. It is easily exploitable over a network with medium attack complexity and no authentication required, leading to complete compromise of confidentiality, integrity, and availability. The FAUCET Risk Score of 95/100 further emphasizes its critical nature. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB (EDB-7928), demonstrating its exploitability. Despite its age and severity, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3CPE matchmatch criteria | cpe:2.3:a:synactis:all_in_the_box.ocx:3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.