vendor:
Baidu Soba
by:
Unknown
7.5
CVSS
HIGH
Remote Code Execution
Unknown
CWE
Product Name: Baidu Soba
Affected Version From: Baidu Soba 5.4
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: Unknown
Platforms Tested: Windows
Unknown
Remote Code Execution in Baidu Soba ActiveX Control
An attacker can exploit this issue to execute hostile code on a victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Successful exploits will allow attackers to execute arbitrary code with the privileges of the affected user; other consequences are possible.
Mitigation:
Unknown