6.4
CVSSv2

CVE-2007-5446

Published: 14/10/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Absolute path traversal vulnerability in a certain ActiveX control in PBEmail7Ax.dll in PBEmail 7 ActiveX Edition allows remote malicious users to create or overwrite arbitrary files via a full pathname in the XmlFilePath argument to the SaveSenderToXml method.

Vulnerable Product Search on Vulmon Subscribe to Product

perfection bytes pbemail 7.0

Exploits

<pre> <b>Found by</b>: Katatafish (karatatata{at}hush{dot}com) <b>software</b>:PBEmail 7 ActiveX Edition <b>Vendor:</b> wwwperfectionbytescom <b>vulnerability</b>: Insecure method SaveSenderToXml(XmlFilePath: BSTR); stdcall; in PBEmail7Axdll <b>Tested on Internet explorer 7 with ...