Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v4p8-cpq3-f35v

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420.

Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420.

EPSS

Процентиль: 90%
0.05464
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
больше 18 лет назад

Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420.

EPSS

Процентиль: 90%
0.05464
Низкий

Дефекты

CWE-22