CVE-2007-5219
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
05/10/2007
Last modified:
09/04/2025
Description
Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLAVSetting module in CyberLink PowerDVD 7.0 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the CreateNewFile method.
Impact
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cyberlink:powerdvd:7.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://osvdb.org/37725
- http://secunia.com/advisories/27039
- http://www.securityfocus.com/bid/25888
- http://www.securitytracker.com/id?1018758=
- http://www.vupen.com/english/advisories/2007/3328
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36902
- https://www.exploit-db.com/exploits/4479
- http://osvdb.org/37725
- http://secunia.com/advisories/27039
- http://www.securityfocus.com/bid/25888
- http://www.securitytracker.com/id?1018758=
- http://www.vupen.com/english/advisories/2007/3328
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36902
- https://www.exploit-db.com/exploits/4479



