PT-2009-2108 · Versalsoft · Versalsoft Http Image Uploader

Publicado

2009-04-07

·

Atualizado

2017-09-29

·

CVE-2008-6638

CVSS v2.0

8.8

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Versalsoft HTTP Image Uploader version 6.0.0.35
Description The issue concerns an insecure method in the Versalsoft HTTP Image Uploader ActiveX control, which allows remote attackers to delete arbitrary files. This is achieved via the RemoveFileOrDir method.
Recommendations For version 6.0.0.35, consider disabling the RemoveFileOrDir method until a patch is available to prevent the deletion of arbitrary files.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6638

Produtos afetados

Versalsoft Http Image Uploader