CVE-2007-4890
Microsoft Visual Studio - Path Traversal
Title source: ruleDescription
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/4394
References (5)
Scores
EPSS
0.2651
EPSS Percentile
96.3%
Details
CWE
CWE-22
Status
published
Products (1)
microsoft/visual_studio
6.0
Published
Sep 14, 2007
Tracked Since
Feb 18, 2026