CVE-2007-4983

N/A Unknown
Published: September 19, 2007 Modified: April 23, 2026
View on NVD

Description

Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic and 7.0.3.3016 allows remote attackers to create or overwrite arbitrary local files via a ..\ (dot dot backslash) in the second argument to the DownloadFromMusicStore method. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for code execution by overwriting JetAudio.exe, which is launched by the control after completion of the method call.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/37737
Source: cve@mitre.org
http://secunia.com/advisories/26787
Source: cve@mitre.org
Vendor Advisory
http://osvdb.org/37737
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26787
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/bid/25723
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1018716
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/3196
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/36693
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/4427
Source: af854a3a-2127-422b-91ae-364da2661108

14 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
47.3%
99th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

cowon_america