Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-4420. PoCs published by shinnai.
AI-analyzed exploit summary This exploit leverages an insecure method in the EDraw Office Viewer Component ActiveX control to download arbitrary files to the victim's system. The HttpDownloadFile method is called without proper security checks, allowing file write operations.
Description
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer Component 5.1 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the HttpDownloadFile method, a different vulnerability than CVE-2007-3168 and CVE-2007-3169.
Exploits (1)
This exploit leverages an insecure method in the EDraw Office Viewer Component ActiveX control to download arbitrary files to the victim's system. The HttpDownloadFile method is called without proper security checks, allowing file write operations.