CVE-2007-5219

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/10/2007
Last modified:
09/04/2025

Description

Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyberlink:powerdvd:7.0:*:*:*:*:*:*:*