PT-2008-4128 · Black Ice · Black Ice Barcode Sdk

Shinnai

·

Published

2008-06-12

·

Updated

2017-09-29

·

CVE-2008-2683

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Black Ice Barcode SDK version 5.01
Description The issue allows remote attackers to force the download and storage of arbitrary files. This is achieved by specifying the origin URL in the first argument to the DownloadImageFileURL method, and the local filename in the second argument.
Recommendations For Black Ice Barcode SDK version 5.01, consider restricting access to the DownloadImageFileURL method until a patch is available. As a temporary workaround, avoid using the DownloadImageFileURL method with untrusted input.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2683

Affected Products

Black Ice Barcode Sdk