CVE-2008-2283
Last modified
CVE-2008-2283 is a vulnerability of currently unknown severity. IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL (aka IDautomation Datamatrix Barcode) 1.6.0.6, (c) the IDAuto.PDF417.1 ActiveX control in IDAutomationPDF417_6.dll (aka IDautomation PDF417 Barcode) 1.6.0.6, and (d) the IDAuto.Aztec.1 ActiveX control in IDAutomationAZTEC.dll (aka IDautomation Aztec Barcode) 1.7.1.0.. EPSS estimates a 6.00% chance of exploitation in the next 30 days.
Description
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL (aka IDautomation Datamatrix Barcode) 1.6.0.6, (c) the IDAuto.PDF417.1 ActiveX control in IDAutomationPDF417_6.dll (aka IDautomation PDF417 Barcode) 1.6.0.6, and (d) the IDAuto.Aztec.1 ActiveX control in IDAutomationAZTEC.dll (aka IDautomation Aztec Barcode) 1.7.1.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Idautomation | Aztec Barcode | 1.7.1.0 |
| Idautomation | Datamatrix Barcode | 1.6.0.6 |
| Idautomation | Linear Barcode | 1.6.0.6 |
| Idautomation | Pdf417 Barcode | 1.6.0.6 |
References
- http://secunia.com/advisories/30246Vendor Advisory
- http://secunia.com/advisories/30246Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2283?
How severe is CVE-2008-2283?
How do I fix CVE-2008-2283?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-2277SQL injection vulnerability in detail.php in Feedback and Ra…
- CVE-2008-2278SQL injection vulnerability in browseproject.php in Freelanc…
- CVE-2008-2279Freelance Auction Script 1.0 stores user passwords in plaint…
- CVE-2008-2280Cross-site scripting (XSS) vulnerability in admin/index.php …
- CVE-2008-2281Cross-zone scripting vulnerability in the Print Table of Lin…
- CVE-2008-2282admin.php in Internet Photoshow and Internet Photoshow Speci…
- CVE-2008-2284PHP remote file inclusion vulnerability in fusebox5.php in F…
- CVE-2008-2285The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LT…
- CVE-2008-2286SQL injection vulnerability in axengine.exe in Symantec Alti…
- CVE-2008-2287Symantec Altiris Deployment Solution 6.8.x and 6.9.x before …
- CVE-2008-2288Symantec Altiris Deployment Solution 6.8.x and 6.9.x before …
- CVE-2008-2289Unspecified vulnerability in a tooltip element in Symantec A…
Are you affected by CVE-2008-2283?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
