5
CVSSv2

CVE-2007-3982

Published: 25/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Absolute path traversal vulnerability in the Data Dynamics ActiveReport (ActiveReports) ActiveX control in actrpt2.dll 2.5 and previous versions allows remote malicious users to create or overwrite arbitrary files via a full pathname in the first argument to the SaveLayout method.

Vulnerable Product Search on Vulmon Subscribe to Product

datadynamics activereports

Exploits

<pre> <code><span style="font: 10pt Courier New;"><span class="general1-symbol">----------------------------------------------------------------------------------------------- <b>Data Dynamics ActiveReport ActiveX Control (actrpt2dll <= 25) "SaveLayout()" Inscure Method</b> url: wwwdatadynamicscom ...