CVE-2007-5219 EXPLOIT
6.4
MEDIUM · CVSS 2.0 · EPSS 15.7% (pctl 97)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method.
Scoring
| CVSS | 6.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
| EPSS | 15.65% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-10-05 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| cyberlink | powerdvd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CyberLink PowerDVD - CreateNewFile Remote Rewrite Denial of Service | 2007-10-01 |
References
- http://osvdb.org/37725
- http://secunia.com/advisories/27039
- http://www.securityfocus.com/bid/25888
- http://www.securitytracker.com/id?1018758
- http://www.vupen.com/english/advisories/2007/3328
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36902
- https://www.exploit-db.com/exploits/4479
- http://osvdb.org/37725
- http://secunia.com/advisories/27039
- http://www.securityfocus.com/bid/25888
- http://www.securitytracker.com/id?1018758
- http://www.vupen.com/english/advisories/2007/3328
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36902
- https://www.exploit-db.com/exploits/4479
→ the Explorer · watch your stack · NVD