Vulnerability Name: | CVE-2007-4890 (CCN-36571) | ||||||||
Assigned: | 2007-09-11 | ||||||||
Published: | 2007-09-11 | ||||||||
Updated: | 2017-09-29 | ||||||||
Summary: | Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. Note: contents can be copied from local files via the Load method. | ||||||||
CVSS v3 Severity: | 9.1 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P) 4.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P/E:POC/RL:U/RC:UR)
7.5 High (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:C/A:C/E:POC/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-22 | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-4890 Source: CCN Type: Microsoft Corporation Web site Microsoft Visual Studio Source: CCN Type: SA26779 Microsoft Visual Studio Two ActiveX Controls Insecure Methods Source: SECUNIA Type: UNKNOWN 26779 Source: MISC Type: UNKNOWN http://shinnai.altervista.org/exploits/txt/TXT_qwFZc3a35RLy5AGxVBjJ.html Source: CCN Type: OSVDB ID: 37107 Microsoft Visual Studio VB To VSI Support Library ActiveX (VBTOVSI.DLL) SaveAs Method Arbitrary File Manipulation Source: BID Type: UNKNOWN 25635 Source: CCN Type: BID-25635 Microsoft Visual Studio VB To VSI Support Library ActiveX Arbitrary File Overwrite Vulnerability Source: XF Type: UNKNOWN visualstudio-vbtovsi-file-overwrite(36571) Source: XF Type: UNKNOWN visualstudio-vbtovsi-file-overwrite(36571) Source: EXPLOIT-DB Type: UNKNOWN 4394 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |