CVE-2007-4583 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 8% (pctl 95)
Patch early
A public exploit exists.
Description
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in ACTi Network Video Recorder (NVR) SP2 2.0 allow remote attackers to (1) create or overwrite arbitrary files via a full pathname in the first argument to the SaveXMLFile method or (2) delete arbitrary files via a full pathname in the argument to the DeleteXMLFile method.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 8.05% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-29 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| acti | network video recorder |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'SaveXMLFile()' Insecure Method | 2007-08-27 |
| exploit-db | NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'DeleteXMLFile()' Insecure Method | 2007-08-27 |
References
- http://osvdb.org/38386
- http://osvdb.org/38387
- http://secunia.com/advisories/26622
- http://www.securityfocus.com/bid/25465
- http://www.vupen.com/english/advisories/2007/2993
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36303
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36304
- https://www.exploit-db.com/exploits/4323
- https://www.exploit-db.com/exploits/4324
- http://osvdb.org/38386
- http://osvdb.org/38387
- http://secunia.com/advisories/26622
- http://www.securityfocus.com/bid/25465
- http://www.vupen.com/english/advisories/2007/2993
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36303
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36304
- https://www.exploit-db.com/exploits/4323
- https://www.exploit-db.com/exploits/4324
→ the Explorer · watch your stack · NVD