CVE-2007-5446

PBEmail 7 ActiveX Edition - Unauthenticated Arbitrary File Write via SaveSenderToXml XmlFilePath Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5446. PoCs published by Katatafish.

AI-analyzed exploit summary This exploit leverages an insecure method in PBEmail 7 ActiveX Edition to overwrite arbitrary files via the SaveSenderToXml method. The PoC demonstrates file overwrite by targeting C:\WINDOWS\system.ini.

Description

Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows remote attackers to create or overwrite arbitrary files via a full pathname in the XmlFilePath argument to the SaveSenderToXml method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Katatafish · htmlremotewindows
https://www.exploit-db.com/exploits/4526

This exploit leverages an insecure method in PBEmail 7 ActiveX Edition to overwrite arbitrary files via the SaveSenderToXml method. The PoC demonstrates file overwrite by targeting C:\WINDOWS\system.ini.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: PBEmail 7 ActiveX Edition
No auth needed
Prerequisites: Victim must have PBEmail 7 ActiveX Edition installed and be using Internet Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4526
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26058
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/43481

Scores

EPSS 0.0579
EPSS Percentile 92.1%

Details

CWE
CWE-22
Status published
Products (1)
perfection_bytes/pbemail 7.0
Published Oct 14, 2007
Tracked Since Feb 18, 2026