CVE-2007-3982

Datadynamics Activereports < 2.5 - Path Traversal

Title source: rule

Description

Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and earlier allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveLayout method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/4208

Scores

EPSS 0.0906
EPSS Percentile 92.7%

Details

Status published
Products (1)
datadynamics/activereports < 2.5
Published Jul 25, 2007
Tracked Since Feb 18, 2026