peter bassill · operator
$ cve CVE-2009-0301 JSON

CVE-2009-0301 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)

Patch early

A public exploit exists.

Description

Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.96% — more likely to be exploited than 80% of all CVEs
On CISA KEVno
Public exploityes
Published2009-01-27
Last modified2026-06-16

Affected (1)

VendorProduct
grid2000flexcell grid control

Public exploits

SourceTitleDate
exploit-dbFlexCell Grid Control 5.6.9 - Remote File Overwrite2009-01-26

References

→ the Explorer  ·  watch your stack  ·  NVD