Novell exteNd Director LocalExec.OCX ActiveX Control Remote Command Execution Vulnerability
BID:24493
Info
Novell exteNd Director LocalExec.OCX ActiveX Control Remote Command Execution Vulnerability
| Bugtraq ID: | 24493 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2923 |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Will Dormann of CERT/CC is credited with the discovery of this vulnerability. |
| Vulnerable: |
Novell exteNd Director 4.1 |
| Not Vulnerable: | |
Discussion
Novell exteNd Director LocalExec.OCX ActiveX Control Remote Command Execution Vulnerability
Novell exteNd Director is prone to a remote command-execution vulnerability because the application fails to sanitize user-supplied data passed through an unspecified URI parameter.
Attackers can leverage this issue to execute arbitrary code in the context of the application using the affected control (typically Internet Explorer).
Novell exteNd Director is prone to a remote command-execution vulnerability because the application fails to sanitize user-supplied data passed through an unspecified URI parameter.
Attackers can leverage this issue to execute arbitrary code in the context of the application using the affected control (typically Internet Explorer).
Exploit / POC
Novell exteNd Director LocalExec.OCX ActiveX Control Remote Command Execution Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Novell exteNd Director LocalExec.OCX ActiveX Control Remote Command Execution Vulnerability
Solution:
The vendor has released Novell security update 3169416 to address this issue; please see the referenced advisories for more information.
Solution:
The vendor has released Novell security update 3169416 to address this issue; please see the referenced advisories for more information.
References
Novell exteNd Director LocalExec.OCX ActiveX Control Remote Command Execution Vulnerability
References:
References: