CVE-2013-2827

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
15/01/2014
Last modified:
11/04/2025

Description

An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wellintech:kingalarm\&event:*:*:*:*:*:*:*:* 2.0.2 (including)
cpe:2.3:a:wellintech:kinggraphic:*:*:*:*:*:*:*:* 3.1 (including)
cpe:2.3:a:wellintech:kingscada:*:*:*:*:*:*:*:* 3.1 (including)