CVE-2008-1647

ChilkatHttp <2.4.0.0 - Code Injection

Title source: llm

Description

The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/5338
exploitdb WORKING POC
htmlremotewindows
https://www.exploit-db.com/exploits/7594

Scores

EPSS 0.0596
EPSS Percentile 90.5%

Classification

CWE
CWE-20
Status draft

Affected Products (1)

chilkat_software/chilkathttp_activex < 2.3.0.0

Timeline

Published Apr 02, 2008
Tracked Since Feb 18, 2026