CVE-2007-4983
Cowon America Jetaudio - Path Traversal
Title source: ruleDescription
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call.
Exploits (1)
References (7)
Scores
EPSS
0.1430
EPSS Percentile
94.4%
Details
CWE
CWE-22
Status
published
Products (2)
cowon_america/jetaudio
7.0.3.3016
cowon_america/jetaudio
7.0.3_basic
Published
Sep 19, 2007
Tracked Since
Feb 18, 2026