CVE-2007-5446
PBEmail 7 ActiveX Edition - Unauthenticated Arbitrary File Write via SaveSenderToXml XmlFilePath Argument
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5446. PoCs published by Katatafish.
AI-analyzed exploit summary This exploit leverages an insecure method in PBEmail 7 ActiveX Edition to overwrite arbitrary files via the SaveSenderToXml method. The PoC demonstrates file overwrite by targeting C:\WINDOWS\system.ini.
Description
Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows remote attackers to create or overwrite arbitrary files via a full pathname in the XmlFilePath argument to the SaveSenderToXml method.
Exploits (1)
This exploit leverages an insecure method in PBEmail 7 ActiveX Edition to overwrite arbitrary files via the SaveSenderToXml method. The PoC demonstrates file overwrite by targeting C:\WINDOWS\system.ini.