9.3
CVSSv2

CVE-2006-3423

Published: 07/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

WebEx Downloader ActiveX Control and WebEx Downloader Java prior to 2.1.0.0 do not validate downloaded components, which allows remote malicious users to execute arbitrary code via a website that activates the GpcUrlRoot and GpcIniFileName ActiveX controls to cause the client to download a DLL file.

Vulnerable Product Search on Vulmon Subscribe to Product

webex communications downloader activexcontrol 2.0.0.7

webex communications downloader java 2.0.0.9