CWE-623: Unsafe ActiveX Control Marked Safe For Scripting
Individual Definition in a New Window
Unsafe ActiveX Control Marked Safe For Scripting
Status: Draft
Weakness ID: 623 (Weakness Variant)
Description
Summary
An ActiveX control is intended for restricted use, but it has
been marked as safe-for-scripting.
Extended Description
This might allow attackers to use dangerous functionality via a web page
that accesses the control, which can lead to different resultant
vulnerabilities, depending on the control's behavior.