6.4
CVSSv2

CVE-2007-5219

Published: 05/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote malicious users to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method.

Vulnerable Product Search on Vulmon Subscribe to Product

cyberlink powerdvd 7.0

Exploits

<!-- CyberLink PowerDVD CLAVSetting Module (CLAVSettingDLL 1001829) arbitrary remote rewrite dos this is installed by default on Acer Travelmate series allows to overwrite files with an empty one extension doesn't matter object safety report: RegKey Safe for Script: False RegKey Safe for Init: False Implements IObjectSafety: True IDisp Safe ...