CVE-2008-1647 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7% (pctl 94)
Patch early
A public exploit exists.
Description
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party information.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.01% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-04-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| chilkat software | chilkathttp activex |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Chilkat FTP - ActiveX (SaveLastError) Insecure Method | 2008-12-28 |
| exploit-db | ChilkatHttp ActiveX 2.3 - Arbitrary Files Overwrite | 2008-04-01 |
References
- http://secunia.com/advisories/29581
- http://www.securityfocus.com/bid/28546
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1207033569.ff.php
- http://www.vupen.com/english/advisories/2008/1050/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45988
- https://www.exploit-db.com/exploits/5338
- http://secunia.com/advisories/29581
- http://www.securityfocus.com/bid/28546
- http://www.shinnai.altervista.org/index.php?mod=02_Forum&group=Security&argument=Remote_performed_exploits&topic=1207033569.ff.php
- http://www.vupen.com/english/advisories/2008/1050/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45988
- https://www.exploit-db.com/exploits/5338
→ the Explorer · watch your stack · NVD