Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4343

Опубликовано: 30 сент. 2008
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:chilkat_software:chilkat_xml_activex_control:*:*:*:*:*:*:*:*
Версия до 3.0.3.0 (включая)

EPSS

Процентиль: 91%
0.06532
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

EPSS

Процентиль: 91%
0.06532
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-20