Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-1112 | First vendor Publication | 2007-04-05 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2) StartBatchUploading, (3) StartStrBatchUploading, or (4) StartUploading methods. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1112 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-36 | Using Unpublished Web Service APIs |
CAPEC-113 | API Abuse/Misuse |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
33850 | Kaspersky Multiple Products AXKLSYSINFOLib.SysInfo ActiveX Multiple Method Ar... |
33849 | Kaspersky Multiple Products AXKLPROD60Lib.KAV60Info ActiveX Multiple Method A... |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Kaspersky AntiVirus KAV60Info ActiveX function call unicode access RuleID : 10434 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Kaspersky AntiVirus KAV60Info ActiveX function call access RuleID : 10433 - Revision : 9 - Type : BROWSER-PLUGINS |
2014-01-10 | Kaspersky AntiVirus KAV60Info ActiveX clsid unicode access RuleID : 10432 - Revision : 5 - Type : WEB-ACTIVEX |
2014-01-10 | Kaspersky AntiVirus KAV60Info ActiveX clsid access RuleID : 10431 - Revision : 10 - Type : BROWSER-PLUGINS |
2014-01-10 | Kaspersky AntiVirus SysInfo ActiveX function call unicode access RuleID : 10430 - Revision : 6 - Type : WEB-ACTIVEX |
2014-01-10 | Kaspersky AntiVirus SysInfo ActiveX function call access RuleID : 10429 - Revision : 9 - Type : BROWSER-PLUGINS |
2014-01-10 | Kaspersky AntiVirus SysInfo ActiveX clsid unicode access RuleID : 10428 - Revision : 5 - Type : WEB-ACTIVEX |
2014-01-10 | Kaspersky AntiVirus SysInfo ActiveX clsid access RuleID : 10427 - Revision : 10 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-04-10 | Name : The remote Windows host contains an application that is prone to various issues. File : kaspersky_av6_mult_vulns.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:45 |
|
2024-11-28 12:11:38 |
|
2021-05-04 12:05:26 |
|
2021-04-22 01:05:59 |
|
2020-05-23 00:19:21 |
|
2018-10-16 21:19:50 |
|
2017-07-29 12:02:03 |
|
2016-04-26 15:48:23 |
|
2014-02-17 10:39:15 |
|
2014-01-19 21:23:56 |
|
2013-05-11 10:19:39 |
|