CVE-2007-5322 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 18.6% (pctl 97)
Patch early
A public exploit exists.
Description
Insecure method vulnerability in the FPOLE.OCX 6.0.8450.0 ActiveX control in Microsoft Visual FoxPro 6.0 allows remote attackers to execute arbitrary programs by specifying them as an argument to the FoxDoCmd function.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 18.58% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-10-09 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | visual foxpro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Visual FoxPro 6.0 - 'FPOLE.OCX' Arbitrary Command Execution | 2007-10-09 |
References
- http://osvdb.org/38487
- http://secunia.com/advisories/27165
- http://shinnai.altervista.org/exploits/txt/TXT_14md9AHOoCycrnk9l095.html
- http://www.securityfocus.com/bid/25977
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37035
- https://www.exploit-db.com/exploits/4506
- http://osvdb.org/38487
- http://secunia.com/advisories/27165
- http://shinnai.altervista.org/exploits/txt/TXT_14md9AHOoCycrnk9l095.html
- http://www.securityfocus.com/bid/25977
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37035
- https://www.exploit-db.com/exploits/4506
→ the Explorer · watch your stack · NVD