PT-2007-7327 · Imesh · Imweb.Dll+1

Published

2007-12-20

·

Updated

2018-10-15

·

CVE-2007-6493

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions iMesh versions 7.1.0.x and earlier IMWeb.dll version 7.0.0.x
Description The issue allows remote attackers to execute arbitrary code via a certain argument to the SetHandler method in the IMWeb.IMWebControl.1 ActiveX control.
Recommendations For iMesh versions 7.1.0.x and earlier, consider disabling the SetHandler method until a patch is available. For IMWeb.dll version 7.0.0.x, restrict access to the IMWeb.IMWebControl.1 ActiveX control to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6493

Affected Products

Imweb.Dll
Imesh