CVE-2008-4453
Last modified
CVE-2008-4453 is a vulnerability of currently unknown severity. The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. EPSS estimates a 10.47% chance of exploitation in the next 30 days.
Description
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dspicture | Light Imaging Toolkit | 4.7.1 |
| Dspicture | Pro Imaging Sdk | 5.7.1 |
References
- http://secunia.com/advisories/31898Vendor Advisory
- http://secunia.com/advisories/31966Vendor Advisory
- http://www.securityfocus.com/bid/31504Exploit, Patch
- http://secunia.com/advisories/31898Vendor Advisory
- http://secunia.com/advisories/31966Vendor Advisory
- http://www.securityfocus.com/bid/31504Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4453?
How severe is CVE-2008-4453?
How do I fix CVE-2008-4453?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4447Cross-site scripting (XSS) vulnerability in actions.php in P…
- CVE-2008-4448Cross-site request forgery (CSRF) vulnerability in actions.p…
- CVE-2008-4449Stack-based buffer overflow in mIRC 6.34 allows remote attac…
- CVE-2008-4450Cross-site scripting (XSS) vulnerability in adodb.php in XAM…
- CVE-2008-4451The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535…
- CVE-2008-4452Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2…
- CVE-2008-4454Directory traversal vulnerability in EKINdesigns MySQL Quick…
- CVE-2008-4455Directory traversal vulnerability in index.php in EKINdesign…
- CVE-2008-4456Cross-site scripting (XSS) vulnerability in the command-line…
- CVE-2008-4457SQL injection vulnerability in inc/inc_statistics.php in Mem…
- CVE-2008-4458SQL injection vulnerability in listings.php in E-Php B2B Tra…
- CVE-2008-4459SQL injection vulnerability in pick_users.php in the groups …
Are you affected by CVE-2008-4453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
