CVE-2008-3879

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
02/09/2008
Last modified:
09/04/2025

Description

The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ultrashareware:ultra_office_control:*:*:*:*:*:*:*:* 2.0.2008.801 (including)