CVE-2007-1682 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 29.6% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 29.61% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-08-27 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| softartisans | xfile |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SoftArtisans XFile FileManager - ActiveX Control Buffer Overflow (Metasploit) | 2010-05-09 |
References
- http://secunia.com/advisories/31615
- http://support.softartisans.com/Support-114.aspx
- http://www.kb.cert.org/vuls/id/914785
- http://www.securityfocus.com/bid/30826
- http://secunia.com/advisories/31615
- http://support.softartisans.com/Support-114.aspx
- http://www.kb.cert.org/vuls/id/914785
- http://www.securityfocus.com/bid/30826
→ the Explorer · watch your stack · NVD