CVE-2007-4891

A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:visual_studio:6.0.0.9782:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio:6.0:*:*:*:*:*:*:*

Information

Published : 2007-09-13 18:17

Updated : 2017-09-28 18:29


NVD link : CVE-2007-4891

Mitre link : CVE-2007-4891


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

microsoft

  • visual_studio