Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-0689

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

DateV是德国的一家软件公司,产品主要为财务、税务、咨询类软件。 DateV存在任意代码执行漏洞。在安装DATEV Base System期间默认会安装一个Datev DVBSExeCall ActiveX控件(DVBSExeCall.ocx)。该控件没有正确地过滤传送给ExecuteExe函数的输入参数,用户受骗访问了恶意网页就可能导致执行任意指令。

AI Predicted 9.8 Difficulty: Trivial EPSS 5.86% · P93
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-0689

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
DateV DVBSExeCall.ocx ActiveX控件远程命令执行漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
DateV是德国的一家软件公司,产品主要为财务、税务、咨询类软件。 DateV存在任意代码执行漏洞。在安装DATEV Base System期间默认会安装一个Datev DVBSExeCall ActiveX控件(DVBSExeCall.ocx)。该控件没有正确地过滤传送给ExecuteExe函数的输入参数,用户受骗访问了恶意网页就可能导致执行任意指令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-0689

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-0689

登录查看更多情报信息。

Vendor Advisories for CVE-2010-0689 (6)

Other References for CVE-2010-0689 (3)

Same Patch Batch · n/a · 2010-02-26 · 23 CVEs total

CVE-2010-0715 IBM WebSphere Portal 'login.jsp' 开放重定向漏洞
CVE-2010-0713 Zenoss 多个跨站请求伪造漏洞
CVE-2010-0712 Zenoss ‘zport/dmd/Events/getJSONEventsInfo‘多个SQL注入漏洞
CVE-2009-4655 Novell eDirectory cookie会话挟持漏洞
CVE-2009-4654 Novell eDirectory HTTPSTK web服务器栈溢出漏洞
CVE-2009-4653 Novell eDirectory dhost模块缓冲区溢出漏洞
CVE-2009-4652 ngIRCd SSL/TLS支持MOTD请求远程拒绝服务漏洞
CVE-2010-0719 Windows平台未明API 输入验证漏洞
CVE-2010-0718 Microsoft Windows平台 Media Player缓冲区溢出漏洞
CVE-2010-0717 MoinMoin ‘cfg.packagepages_actions_excluded‘ 默认配置 未明漏洞
CVE-2010-0716 Microsoft SharePoint ' _layouts/Upload.aspx' 跨站脚本攻击漏洞
CVE-2010-0720 Systemsoftware Erotik Auktionshaus 'news.php' SQL注入漏洞
CVE-2010-0714 IBM产品Web Content Management组件登录页面跨站脚本漏洞
CVE-2010-0669 Moinmo MoinMoin 未明安全漏洞
CVE-2010-0668 Moinmo MoinMoin 多个未明安全漏洞
CVE-2010-0667 MoinMoin 敏感信息泄露漏洞
CVE-2005-4886 Linux内核 ‘security/selinux/hooks.c’ 拒绝服务漏洞
CVE-2010-0725 Mhd_Zaher_Ghaibeh Arab Cart 'showimg.php'跨站脚本攻击漏洞
CVE-2010-0724 Mhd_Zaher_Ghaibeh Arab Cart 'showimg.php' SQL注入漏洞
CVE-2010-0723 Mhproducts Ero Auktion 'news.php' SQL注入漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-0689

No comments yet


Leave a comment