CVE-2007-3633
published 2007-07-10CVE-2007-3633: Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or…
PriorityP430medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EXPLOIT
EPSS
2.88%
85.1th percentile
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chilkat_software | asp_string | — | — |
| chilkat_software | chilkat_zip_activex_control | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4p94-gh8r-23m2: Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2
ghsa_unreviewed·2022-05-01
CVE-2007-3633 [MEDIUM] GHSA-4p94-gh8r-23m2: Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.
GHSA
GHSA-hx46-g3jf-9qgx: Absolute path traversal vulnerability in a certain ActiveX control in CkString
ghsa_unreviewed·2022-05-01·CVSS 6.4
CVE-2007-4252 [MEDIUM] GHSA-hx46-g3jf-9qgx: Absolute path traversal vulnerability in a certain ActiveX control in CkString
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveToFile method, a different vulnerability than CVE-2007-3633.
No detection rules found.
No writeups or analysis indexed.
http://osvdb.org/37676http://secunia.com/advisories/25962http://secunia.com/advisories/48967http://secunia.com/advisories/48968http://www.securityfocus.com/bid/24806http://www.vupen.com/english/advisories/2007/2464https://exchange.xforce.ibmcloud.com/vulnerabilities/35294https://www.exploit-db.com/exploits/4160http://osvdb.org/37676http://secunia.com/advisories/25962http://secunia.com/advisories/48967http://secunia.com/advisories/48968http://www.securityfocus.com/bid/24806http://www.vupen.com/english/advisories/2007/2464https://exchange.xforce.ibmcloud.com/vulnerabilities/35294https://www.exploit-db.com/exploits/4160
2007-07-10
Published