CVE-2008-3879

Ultra Office Control 2.0.2008.801 - RCE

Title source: llm

Description

The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmldoswindows
https://www.exploit-db.com/exploits/6319

Scores

EPSS 0.1216
EPSS Percentile 93.8%

Details

CWE
CWE-20
Status published
Products (1)
ultrashareware/ultra_office_control < 2.0.2008.801
Published Sep 02, 2008
Tracked Since Feb 18, 2026