Lucene search

K
cve[email protected]CVE-2008-4453
HistoryOct 06, 2008 - 11:25 p.m.

CVE-2008-4453

2008-10-0623:25:50
CWE-264
web.nvd.nist.gov
27
gdpicture
imaging toolkit
pro imaging sdk
activex control
remote attackers
arbitrary files
saveaspdf
exploitability
remote code execution
hcp:// urls

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.18 Low

EPSS

Percentile

96.2%

The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
dspicturelight_imaging_toolkitMatch4.7.1
OR
dspicturepro_imaging_sdkMatch5.7.1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.18 Low

EPSS

Percentile

96.2%

Related for CVE-2008-4453