Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-5826. PoCs published by shinnai.
AI-analyzed exploit summary This exploit leverages an insecure method in the EDraw Flowchart ActiveX Control (EDImage.ocx v. 2.0.2005.1104) to download and execute arbitrary files via the HttpDownloadFile method. The PoC demonstrates a click-based trigger to download a file from a remote URL to a local path.
Description
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420.
Exploits (1)
This exploit leverages an insecure method in the EDraw Flowchart ActiveX Control (EDImage.ocx v. 2.0.2005.1104) to download and execute arbitrary files via the HttpDownloadFile method. The PoC demonstrates a click-based trigger to download a file from a remote URL to a local path.