Sploitus

CVE-2007-4891

6 known exploits for CVE-2007-4891

A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.

Affected products
Visual Studio
Microsoft Visual Studio
= 6.0, 6.0.0.9782
CVSS 2.0
6.8 MEDIUM
EPSS
31.0% (98th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2007-09-14
CVE-2007-4891 at NVD
Authoritative description, scoring and affected products

6 known exploits for CVE-2007-4891

Proof-of-concept code and exploit modules indexed by Sploitus