CVE-2007-5815

SonicWall SSL-VPN <2.1-2.5 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5815. PoCs published by Will Dormann.

AI-analyzed exploit summary This exploit demonstrates a file deletion vulnerability in the SonicWALL SSL VPN Client via an ActiveX control. It creates an object of 'MLWebCacheCleaner.WebCacheCleaner.1' and calls the 'FileDelete' method to delete an arbitrary file.

Description

Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 before 2.5, allows remote attackers to delete arbitrary files via a full pathname in the argument to the FileDelete method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Will Dormann · textremotewindows
https://www.exploit-db.com/exploits/30730

This exploit demonstrates a file deletion vulnerability in the SonicWALL SSL VPN Client via an ActiveX control. It creates an object of 'MLWebCacheCleaner.WebCacheCleaner.1' and calls the 'FileDelete' method to delete an arbitrary file.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: SonicWALL SSL VPN Client 1.3.0.3
No auth needed
Prerequisites: ActiveX controls enabled in the target environment · Access to execute VBScript on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3696
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3342
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26288
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27469
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/483097/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38221
Exploit x_refsource_misc
http://www.sec-consult.com/303.html

Scores

EPSS 0.0453
EPSS Percentile 90.3%

Details

CWE
CWE-22
Status published
Products (2)
sonicwall/ssl_vpn2000\/4000 < 2.5
sonicwall/ssl_vpn_200 < 2.1
Published Nov 05, 2007
Tracked Since Feb 18, 2026