37692vdb entry
http://osvdb.org/37692 CVE-2007-3883
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
Record summary
CVE-2007-3883 has a selected CVSS score of 5.1; EIP currently links 2 catalogued exploits.
Description
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite files via a full pathname in (1) the second argument to the Save method, or the first argument to the (2) SaveLayoutChanges or (3) SaveMenuUsageData method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBData Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure MethodsExploitDB exploitby shinnaiNot analyzed1 file
ExploitDBData Dynamics ActiveBar (Actbar3.ocx 3.2) - Multiple Insecure MethodsExploitDB exploitby shinnaiNot analyzed1 file
References
726098Third-party advisory
http://secunia.com/advisories/26098 24959vdb entry
http://www.securityfocus.com/bid/24959 datadynamics-actbar3-file-overwrite(35471)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/35471 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-3883 4190exploit
https://www.exploit-db.com/exploits/4190 5395exploit
https://www.exploit-db.com/exploits/5395