37676vdb entry
http://osvdb.org/37676 CVE-2007-3633
Chilkat Zip ActiveX Component 12.4 - Multiple Insecure Methods
Record summary
CVE-2007-3633 has a selected CVSS score of 6.4; EIP currently links 1 catalogued exploit.
Description
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBChilkat Zip ActiveX Component 12.4 - Multiple Insecure MethodsExploitDB exploitby shinnaiNot analyzed1 file
References
925962Third-party advisory
http://secunia.com/advisories/25962 48967Third-party advisory
http://secunia.com/advisories/48967 48968Third-party advisory
http://secunia.com/advisories/48968 24806vdb entry
http://www.securityfocus.com/bid/24806 ADV-2007-2464vdb entry
http://www.vupen.com/english/advisories/2007/2464 chilkat-zip-chilkatzip2-file-overwrite(35294)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35294 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-3633 4160exploit
https://www.exploit-db.com/exploits/4160