Title : Chilkat HTTP ActiveX Component File Corruption Vulnerability VUPEN ID : VUPEN/ADV-2008-1050 CVE ID : CVE-2008-1647
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-01
Technical Description
A vulnerability has been identified in Chilkat HTTP ActiveX Component, which could be exploited by attackers to corrupt arbitrary files. This issue is caused by a design error in the "SaveLastError()" method within the "ChilkatHttp.dll" library, which could be exploited by attackers to overwrite and corrupt arbitrary files on a vulnerable system by tricking a user into visiting a malicious web page.