Vulnerabilities > CVE-2007-3633 - Arbitrary File Overwrite vulnerability in Chilkat Software Chilkat ZIP Activex Control 12.4.2.0

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
chilkat-software
exploit available

Summary

Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method.

Vulnerable Configurations

Part Description Count
Application
Chilkat_Software
1

Exploit-Db

descriptionChilkat Zip ActiveX Component 12.4 Multiple Insecure Methods Exploit. CVE-2007-3633. Remote exploit for windows platform
fileexploits/windows/remote/4160.html
idEDB-ID:4160
last seen2016-01-31
modified2007-07-07
platformwindows
port
published2007-07-07
reportershinnai
sourcehttps://www.exploit-db.com/download/4160/
titleChilkat Zip ActiveX Component 12.4 - Multiple Insecure Methods Exploit
typeremote