---
cve: "CVE-2008-4343"
severity: "LOW"
cvss: 3.1
epss: "8.7%"
vendor: "n/a"
kev: false
exploited: false
published: "2008-09-30 17:22:09"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T08:11:02+02:00"
---

# CVE-2008-4343

> 3.1 LOW · 🧪 PoC

## Beschreibung

The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method.  NOTE: this issue might only be exploitable in limited environments or non-default browser settings.  NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

## Exploit-Evidenz

- [EDB-6537 — Chilkat XML - ActiveX Arbitrary File Creation/Execution](https://www.exploit-db.com/exploits/6537) ✅

## Referenzen

- <http://secunia.com/advisories/31951>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/45333>
- <https://www.exploit-db.com/exploits/6537>
- <http://www.securityfocus.com/bid/31332>
- <http://www.shinnai.net/xplits/TXT_rNowA1916DKFNUF48NyS>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2008-4343) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
