An unspecified ActiveX control in SiteKiosk before 6.5.150 is installed "safe for scripting", which allows local users to bypass security protections and read arbitrary files via certain functions. This vulnerability is addressed in the following product release:
SiteKiosk, SiteKiosk, 6.5.150
Publication date: Thu, 14 Dec 2006 06:28:00 +0000