9.3

CVE-2007-4105

A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing "a link to download and a file to execute," possibly involving remote file inclusion.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BaiduSoba Search Bar Version5.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.33% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/26256
Vendor Advisory
http://www.fortiguardcenter.com/advisory/FGA-2007-10.html
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/475320/100/0/threaded
http://www.securityfocus.com/bid/25121
http://www.vupen.com/english/advisories/2007/2699
https://exchange.xforce.ibmcloud.com/vulnerabilities/35692