| Vulnerability Name: | CVE-2007-2923 (CCN-34898) | ||||||||
| Assigned: | 2007-06-15 | ||||||||
| Published: | 2007-06-15 | ||||||||
| Updated: | 2017-07-29 | ||||||||
| Summary: | The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands. | ||||||||
| CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2007-2923 Source: OSVDB Type: UNKNOWN 37318 Source: CCN Type: SA25710 Novell exteNd Director LocalExec ActiveX Control "launch()" Insecure Method Source: SECUNIA Type: UNKNOWN 25710 Source: CCN Type: SECTRACK ID: 1018258 Novell exteNd Director ActiveX Control Lets Remote Users Execute Arbitrary Code Source: CCN Type: US-CERT VU#793433 Novell exteNd Director 4.1 LocalExec ActiveX control fails to restrict access to dangerous methods Source: CERT-VN Type: US Government Resource VU#793433 Source: CONFIRM Type: UNKNOWN http://www.novell.com/documentation/nedse41/readmesp2.txt Source: CCN Type: OSVDB ID: 37318 Novell Multiple Products LocalExec ActiveX (LocalExec.ocx) launch() Method Arbitrary Command Execution Source: BID Type: Exploit, Patch 24493 Source: CCN Type: BID-24493 Novell exteNd Director LocalExec.OCX ActiveX Control Remote Command Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1018258 Source: VUPEN Type: UNKNOWN ADV-2007-2235 Source: XF Type: UNKNOWN novell-localexec-command-execution(34898) Source: XF Type: UNKNOWN novell-localexec-command-execution(34898) Source: CCN Type: Novell Security Alert Document ID: 3169416 Potential Security Vulnerability in exteNd Director Standard 4.1 with ActiveX control Source: CONFIRM Type: UNKNOWN https://secure-support.novell.com/KanisaPlatform/Publishing/360/3169416_f.SAL_Public.html | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||