CVE-2008-5002
high · 9.3Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.
9.3
CVSS
40.7%
EPSS (exploit prob.)
99th
EPSS percentile
2008-11-10
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| chilkat_software | chilkat_crypt_activex_control | 2.1 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/32513
- http://securityreason.com/securityalert/4571
- http://www.securityfocus.com/bid/32073
- http://www.vupen.com/english/advisories/2008/2998
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46315
- https://www.exploit-db.com/exploits/6963
- http://secunia.com/advisories/32513
- http://securityreason.com/securityalert/4571
- http://www.securityfocus.com/bid/32073
- http://www.vupen.com/english/advisories/2008/2998
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46315
- https://www.exploit-db.com/exploits/6963
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-5002