CVE-2007-4067 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7% (pctl 94)
Patch early
A public exploit exists.
Description
Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the GetToFile method. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 6.97% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-07-30 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| clever components | internet activex suite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Clever Internet ActiveX Suite 6.2 - Arbitrary File Download/Overwrite | 2007-07-25 |
References
- http://secunia.com/advisories/26213
- http://www.attrition.org/pipermail/vim/2007-July/001729.html
- http://www.securityfocus.com/bid/25063
- http://www.vupen.com/english/advisories/2007/2659
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35590
- https://www.exploit-db.com/exploits/4226
- http://secunia.com/advisories/26213
- http://www.attrition.org/pipermail/vim/2007-July/001729.html
- http://www.securityfocus.com/bid/25063
- http://www.vupen.com/english/advisories/2007/2659
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35590
- https://www.exploit-db.com/exploits/4226
→ the Explorer · watch your stack · NVD