CVE-2008-4343
Last modified
CVE-2008-4343 is a vulnerability of currently unknown severity. The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. EPSS estimates a 8.68% chance of exploitation in the next 30 days.
Description
The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Chilkat Software | Chilkat Xml Activex Control | <= 3.0.3.0 |
References
- http://secunia.com/advisories/31951Vendor Advisory
- http://www.shinnai.net/xplits/TXT_rNowA1916DKFNUF48NySExploit, URL Repurposed
- http://secunia.com/advisories/31951Vendor Advisory
- http://www.shinnai.net/xplits/TXT_rNowA1916DKFNUF48NySExploit, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4343?
How severe is CVE-2008-4343?
How do I fix CVE-2008-4343?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4337Cross-site scripting (XSS) vulnerability in Bitweaver 2.0.2 …
- CVE-2008-4338SQL injection vulnerability in the brilliant_gallery_checkli…
- CVE-2008-4339Unspecified vulnerability in the Java Administration GUI (jn…
- CVE-2008-4340Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attack…
- CVE-2008-4341add.php in MyBlog 0.9.8 and earlier allows remote attackers …
- CVE-2008-4342NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.…
- CVE-2008-4344SQL injection vulnerability in cat.php in 6rbScript allows r…
- CVE-2008-4345SQL injection vulnerability in download.php in WebPortal CMS…
- CVE-2008-4346Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.…
- CVE-2008-4347SQL injection vulnerability in newskom.php in Powie pNews 2.…
- CVE-2008-4348SQL injection vulnerability in photo.php in PHPortfolio, pos…
- CVE-2008-4349Multiple cross-site scripting (XSS) vulnerabilities in news.…
Are you affected by CVE-2008-4343?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
