CVE-2007-3633
Chilkat Zip ActiveX Control - Absolute Path Traversal via SaveLastError Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3633. PoCs published by shinnai.
AI-analyzed exploit summary This exploit leverages insecure methods in Chilkat Zip ActiveX (SaveLastError) to overwrite system.ini, demonstrating arbitrary file write vulnerability. It is a simple VBScript-based PoC targeting a specific ActiveX control.
Description
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.
Exploits (1)
This exploit leverages insecure methods in Chilkat Zip ActiveX (SaveLastError) to overwrite system.ini, demonstrating arbitrary file write vulnerability. It is a simple VBScript-based PoC targeting a specific ActiveX control.