6.8
CVSSv2

CVE-2007-4891

Published: 14/09/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and previous versions in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote malicious users to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft visual studio 6.0.0.9782

microsoft visual studio 6.0

Exploits

<pre> <code><span style="font: 10pt Courier New;"><span class="general1-symbol"><body bgcolor="#E0E0E0">------------------------------------------------------------------------------------------------------ <b>Microsoft Visual Studio 60 PDWizard (PDWizardocx <= 6009782) Remote Arbitrary Command Execution ...