39629vdb entry
http://osvdb.org/39629 CVE-2007-4428
Lhaz 1.33 Arbitrary Code Execution
Record summary
CVE-2007-4428 has a selected CVSS score of 6.8.
Description
Lhaz 1.33 allows remote attackers to execute arbitrary code via unknown vectors, as actively exploited in August 2007 by the Exploit-LHAZ.a gzip file, a different issue than CVE-2006-4116.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 20, 2007 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| VulnCheck | Version data not supplied | ||
References
826532Third-party advisory
http://secunia.com/advisories/26532 vil.mcafeesecurity.com
http://vil.mcafeesecurity.com/vil/content/v_142976.htm avertlabs.com
http://www.avertlabs.com/research/blog/index.php/2007/08/17/targeted-zero-day-attack-against-free-tools-lhaz 25351vdb entry
http://www.securityfocus.com/bid/25351 ADV-2007-2930vdb entry
http://www.vupen.com/english/advisories/2007/2930 lhaz-zip-code-execution(36120)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/36120 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-4428