Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-4891

Опубликовано: 14 сент. 2007
Источник: nvd
CVSS2: 6.8
EPSS Средний

Описание

A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:visual_studio:6.0:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:6.0.0.9782:*:*:*:*:*:*:*

EPSS

Процентиль: 98%
0.51667
Средний

6.8 Medium

CVSS2

Дефекты

CWE-78

Связанные уязвимости

github
почти 4 года назад

A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.

EPSS

Процентиль: 98%
0.51667
Средний

6.8 Medium

CVSS2

Дефекты

CWE-78