PoC Index

CVE-2007-4982

HIGH 10.0EPSS 10.4%

Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some of these details are obtained from third party information.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
10.42% chance of exploitation in the next 30 days, 95th percentile
Published
2007-09-19
Updated
2024-08-07

ExploitDB entries (1)

References

Related