Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-4031. PoCs published by h07.
AI-analyzed exploit summary This exploit leverages a vulnerability in Nessus Vulnerability Scanner 3.0.6 ActiveX control to delete arbitrary files on the target system via the deleteReport() method. The exploit is triggered when a user visits the malicious HTML page in Internet Explorer.
Description
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll.
Exploits (2)
This exploit leverages a vulnerability in Nessus Vulnerability Scanner 3.0.6 ActiveX control to delete arbitrary files on the target system via the deleteReport() method. The exploit is triggered when a user visits the malicious HTML page in Internet Explorer.
This HTML file exploits a vulnerability in Nessus Vulnerability Scanner 3.0.6 ActiveX control to achieve remote code execution by writing a malicious batch file to the startup folder. The exploit leverages the 'addsetConfig' and 'saveNessusRC' methods to execute arbitrary commands.