peter bassill · operator
$ cve CVE-2007-4067 JSON

CVE-2007-4067 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 7% (pctl 94)

Patch early

A public exploit exists.

Description

Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the GetToFile method. NOTE: some of these details are obtained from third party information.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS6.97% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2007-07-30
Last modified2026-06-16

Affected (1)

VendorProduct
clever componentsinternet activex suite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD