The ExecuteExe method in the DVBSExeCall Control ActiveX control 1.0.0.1 in DVBSExeCall.ocx in DATEV Base System (aka Grundpaket Basis) allows remote attackers to execute arbitrary commands via unspecified vectors. Per: http://cwe.mitre.org/data/definitions/77.html
"CWE-77: Improper Sanitization of Special Elements used in a Command ('Command Injection')"
Publication date: Sat, 27 Feb 2010 01:30:00 +0000