CVE-2007-4031
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.
- Affected products
- Nessus, Nessus Activex Control, Nessus Vulnerability Scanner
- Nessus Vulnerability Scanner
- = 3.0.6
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- EPSS
- 5.7% (93th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2007-07-27
CVE-2007-4031 at NVD
2 known exploits for CVE-2007-4031
Proof-of-concept code and exploit modules indexed by Sploitus