PT-2009-1966 · Visagesoft · Visagesoft Expert Pdf Editorx
Marco Torti
·
Publicado
2009-03-20
·
Atualizado
2017-09-29
·
CVE-2008-6496
CVSS v2.0
8.8
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VISAGESOFT eXPert PDF EditorX version 1.0.200.0
Description
The issue concerns an insecure method in the VSPDFEditorX.VSPDFEdit ActiveX control, which allows remote attackers to create or overwrite arbitrary files. This is achieved by exploiting the
extractPagesToFile method, specifically through its first argument.Recommendations
For version 1.0.200.0, consider disabling the
extractPagesToFile method as a temporary workaround until a patch is available. Restrict access to the VSPDFEditorX.VSPDFEdit ActiveX control to minimize the risk of exploitation. Avoid using the first argument in the extractPagesToFile method in the affected ActiveX control until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Visagesoft Expert Pdf Editorx