A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request containing a link to download and a file to execute, possibly involving remote file inclusion.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Soba_search_bar | Baidu | 5.4 (including) | 5.4 (including) |