CVE-2008-4342
Last modified
CVE-2008-4342 is a vulnerability of currently unknown severity. NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. EPSS estimates a 17.20% chance of exploitation in the next 30 days.
Description
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Burnaware Technologies | Burnaware | 2.1.3 | Unknown |
| Impressum | Cdburnerxp | 4.2.1.976 | — |
| Numedia Soft | Numedia Dvd Burning Sdk | 1.008 | — |
References
- http://secunia.com/advisories/31936Vendor Advisory
- http://secunia.com/advisories/31949Vendor Advisory
- http://secunia.com/advisories/31950Vendor Advisory
- http://secunia.com/advisories/32455Vendor Advisory
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcqExploit, URL Repurposed
- http://www.vupen.com/english/advisories/2008/2663Vendor Advisory
- http://secunia.com/advisories/31936Vendor Advisory
- http://secunia.com/advisories/31949Vendor Advisory
- http://secunia.com/advisories/31950Vendor Advisory
- http://secunia.com/advisories/32455Vendor Advisory
- http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcqExploit, URL Repurposed
- http://www.vupen.com/english/advisories/2008/2663Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4342?
How severe is CVE-2008-4342?
How do I fix CVE-2008-4342?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4336Cross-site scripting (XSS) vulnerability in album.php in Ato…
- CVE-2008-4337Cross-site scripting (XSS) vulnerability in Bitweaver 2.0.2 …
- CVE-2008-4338SQL injection vulnerability in the brilliant_gallery_checkli…
- CVE-2008-4339Unspecified vulnerability in the Java Administration GUI (jn…
- CVE-2008-4340Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attack…
- CVE-2008-4341add.php in MyBlog 0.9.8 and earlier allows remote attackers …
- CVE-2008-4343The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (Chilka…
- CVE-2008-4344SQL injection vulnerability in cat.php in 6rbScript allows r…
- CVE-2008-4345SQL injection vulnerability in download.php in WebPortal CMS…
- CVE-2008-4346Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.…
- CVE-2008-4347SQL injection vulnerability in newskom.php in Powie pNews 2.…
- CVE-2008-4348SQL injection vulnerability in photo.php in PHPortfolio, pos…
Are you affected by CVE-2008-4342?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
