PT-2008-6095 · Visagesoft · Visagesoft Expert Pdf Viewer X

Marco Torti

·

Publicado

2008-11-04

·

Atualizado

2017-09-29

·

CVE-2008-4919

CVSS v2.0

8.8

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions VISAGESOFT eXPert PDF Viewer X ActiveX control version 3.0.990.0
Description The issue allows remote attackers to overwrite arbitrary files by providing a full pathname to the savePageAsBitmap method. This method is part of the VSPDFViewerX.ocx ActiveX control.
Recommendations For version 3.0.990.0, consider disabling the savePageAsBitmap method until a patch is available to prevent remote attackers from overwriting arbitrary files.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4919

Produtos afetados

Visagesoft Expert Pdf Viewer X