CVE-2007-3982

Datadynamics Activereports < 2.5 - Path Traversal

Title source: rule

Description

Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and earlier allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveLayout method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/4208

Scores

EPSS 0.0870
EPSS Percentile 92.3%

Classification

Status draft

Affected Products (1)

datadynamics/activereports < 2.5

Timeline

Published Jul 25, 2007
Tracked Since Feb 18, 2026