Vulnerability Description
The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.
CVSS Score
10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Vfp Ole Server Activex Control | All versions |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.org/0801-exploits/msvfpole-exec.txt
- http://secunia.com/advisories/28417
- http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.htmlExploit
- http://www.securityfocus.com/bid/27199
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39559
- https://www.exploit-db.com/exploits/4875
- http://packetstormsecurity.org/0801-exploits/msvfpole-exec.txt
- http://secunia.com/advisories/28417
- http://shinnai.altervista.org/exploits/txt/TXT_rNowA1916DKFNUF48NyS.htmlExploit
- http://www.securityfocus.com/bid/27199
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39559
- https://www.exploit-db.com/exploits/4875
FAQ
What is CVE-2008-0235?
CVE-2008-0235 is a vulnerability with a CVSS score of 10.0 (HIGH). The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.
How severe is CVE-2008-0235?
CVE-2008-0235 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0235?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Vfp Ole Server Activex Control.