Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-5826
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-5826

Description:
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/38223

SAID
  Secunia Advisory: SA27462

OSVDB
  38415

MISC
  http://shinnai.altervista.org/exploits/txt/TXT_3kXDua0a0Tl5Vm5LU3ms.html

MILW0RM
  http://www.milw0rm.com/exploits/4598

BID
  26308


Return to the previous page.