PT-2009-2491 · Chilkat · Chilkat Software Imap Activex Control+1
E.Wizz!
·
Published
2009-08-21
·
Updated
2017-09-29
·
CVE-2008-7022
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Chilkat Software IMAP ActiveX control version ChilkatMail2.ChilkatMailMan2.1
Description
The issue is related to an insecure method in the ChilkatMail v7 9.dll component of the Chilkat Software IMAP ActiveX control. This allows remote attackers to execute arbitrary programs via the
LoadXmlEmail method.Recommendations
For version ChilkatMail2.ChilkatMailMan2.1, as a temporary workaround, consider disabling the
LoadXmlEmail method until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chilkat Software Imap Activex Control
Chilkatmail V7 9.Dll