CVE-2007-4890: Path Traversal
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1.0.0.0 in Microsoft Visual Studio 6.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the SaveAs method. NOTE: contents can be copied from local files via the Load method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4890?
CVE-2007-4890 is considered high severity due to its potential to allow arbitrary file overwriting.
How do I fix CVE-2007-4890?
To fix CVE-2007-4890, upgrade to a newer version of Microsoft Visual Studio that no longer contains the vulnerable ActiveX control.
What impact does CVE-2007-4890 have on users?
CVE-2007-4890 allows remote attackers to create or overwrite arbitrary files on a user's system, leading to data corruption or unauthorized access.
What software is affected by CVE-2007-4890?
CVE-2007-4890 affects Microsoft Visual Studio 6.0 and specifically the VBTOVSI.DLL ActiveX control.
Can CVE-2007-4890 be exploited remotely?
Yes, CVE-2007-4890 can be exploited remotely through special crafted calls to the vulnerable SaveAs method.