CVE-2020-7806

Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Control. It allows attacker to cause remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:tobesoft:xplatform:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:37

Type Values Removed Values Added
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 7.8
References () http://support.tobesoft.co.kr/Support/index.html - Vendor Advisory () http://support.tobesoft.co.kr/Support/index.html - Vendor Advisory
References () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35359 - Third Party Advisory () https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35359 - Third Party Advisory

Information

Published : 2020-05-06 13:15

Updated : 2024-11-21 05:37


NVD link : CVE-2020-7806

Mitre link : CVE-2020-7806

CVE.ORG link : CVE-2020-7806


JSON object : View

Products Affected

microsoft

  • windows

tobesoft

  • xplatform
CWE
CWE-494

Download of Code Without Integrity Check