Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-0313

Опубликовано: 08 апр. 2008
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote attackers to execute arbitrary code via a remote (1) WebDAV or (2) SMB share.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:symantec:norton_360:1.0:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2007:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_antivirus:2008:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2007:*:*:*:*:*:*:*
cpe:2.3:a:symantec:norton_internet_security:2008:*:*:*:*:*:*:*
cpe:2.3:a:symantec:system_works:2006:*:*:*:*:*:*:*
cpe:2.3:a:symantec:system_works:2007:*:*:*:*:*:*:*
cpe:2.3:a:symantec:system_works:2008:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06221
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location of the AutoFix Tool, which allows remote attackers to execute arbitrary code via a remote (1) WebDAV or (2) SMB share.

EPSS

Процентиль: 91%
0.06221
Низкий

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other