Lucene search

K
cveMitreCVE-2007-3785
HistoryJul 15, 2007 - 11:30 p.m.

CVE-2007-3785

2007-07-1523:30:00
mitre
web.nvd.nist.gov
29
cve-2007-3785
absolute path traversal
activex control
pgpbbox.dll
eldos secureblackbox
sbb
remote attackers
arbitrary files
savetofile method

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.009

Percentile

82.7%

Absolute path traversal vulnerability in a certain ActiveX control in PGPBBox.dll in EldoS SecureBlackbox (sbb) 5.1.0.112 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveToFile method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected configurations

Nvd
Node
eldos_corporationsecureblackboxMatch5.1.0.112
VendorProductVersionCPE
eldos_corporationsecureblackbox5.1.0.112cpe:2.3:a:eldos_corporation:secureblackbox:5.1.0.112:*:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:P/A:P

AI Score

6.6

Confidence

High

EPSS

0.009

Percentile

82.7%

Related for CVE-2007-3785