Sploitus

CVE-2007-4061

1 known exploit for CVE-2007-4061

Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the saveNessusRC method, which writes text specified by the addsetConfig method, possibly related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Nessus Vulnerability Scanner
= 3.0.6
Fix
Available
CVSS 2.0
9.3 HIGH
EPSS
11.2% (96th percentile)
NVD status
Modified
Published
2007-07-30
CVE-2007-4061 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2007-4061

Proof-of-concept code and exploit modules indexed by Sploitus