PT-2007-4748 · Hewlett Packard · Hp Photo Digital Imaging

Callax

·

Published

2007-06-29

·

Updated

2018-10-16

·

CVE-2007-3487

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hewlett-Packard (HP) Photo Digital Imaging version 2.0.0.133
Description The issue concerns an absolute path traversal in a certain ActiveX control in the hpqxml.dll file, which allows remote attackers to create or overwrite arbitrary files. This is achieved by manipulating the argument to the saveXMLAsFile method.
Recommendations For version 2.0.0.133, consider restricting access to the saveXMLAsFile method until a patch is available. Additionally, avoid using the saveXMLAsFile method with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-3487

Affected Products

Hp Photo Digital Imaging