CVE-2007-5322: OS Command Injection
Published Oct 9, 2007
·Updated
Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function.
Affected Software
1 affected component
Microsoft Visual FoxPro=6.0
Event History
Oct 9, 2007
CVE Published
10:17 PM
Oct 10, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5322?
CVE-2007-5322 is rated as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2007-5322?
To fix CVE-2007-5322, users should update to a secure version of Microsoft Visual FoxPro that addresses this vulnerability.
3
What does CVE-2007-5322 exploit?
CVE-2007-5322 exploits an insecure method in the FPOLE.OCX ActiveX control allowing arbitrary command execution.
4
Which software versions are affected by CVE-2007-5322?
CVE-2007-5322 affects Microsoft Visual FoxPro version 6.0 specifically.
5
Can CVE-2007-5322 be exploited remotely?
Yes, CVE-2007-5322 can be exploited remotely by attackers through crafted input to the FoxDoCmd function.