CVE-2008-4453
Last modified
CVE-2008-4453 is a vulnerability of currently unknown severity. The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. EPSS estimates a 10.47% chance of exploitation in the next 30 days.
Description
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dspicture | Light Imaging Toolkit | 4.7.1 |
| Dspicture | Pro Imaging Sdk | 5.7.1 |
References
- http://secunia.com/advisories/31898Vendor Advisory
- http://secunia.com/advisories/31966Vendor Advisory
- http://www.securityfocus.com/bid/31504Exploit, Patch
- http://secunia.com/advisories/31898Vendor Advisory
- http://secunia.com/advisories/31966Vendor Advisory
- http://www.securityfocus.com/bid/31504Exploit, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4453?
How severe is CVE-2008-4453?
How do I fix CVE-2008-4453?
Are you affected by CVE-2008-4453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
