PT-2009-2108 · Versalsoft · Versalsoft Http Image Uploader

Published

2009-04-07

·

Updated

2017-09-29

·

CVE-2008-6638

CVSS v2.0

8.8

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Versalsoft HTTP Image Uploader version 6.0.0.35
Description The issue concerns an insecure method in the Versalsoft HTTP Image Uploader ActiveX control, which allows remote attackers to delete arbitrary files. This is achieved via the RemoveFileOrDir method.
Recommendations For version 6.0.0.35, consider disabling the RemoveFileOrDir method until a patch is available to prevent the deletion of arbitrary files.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6638

Affected Products

Versalsoft Http Image Uploader