CVE-2008-7168
Last modified
CVE-2008-7168 is a vulnerability of currently unknown severity. Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.. EPSS estimates a 5.65% chance of exploitation in the next 30 days.
Description
Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Uusee | Uusee | 4.0.0.32_2008 |
| Uusee | Uuupgrade.Ocx | 3.0.2.12 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-7168?
How severe is CVE-2008-7168?
How do I fix CVE-2008-7168?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-7162Buffer overflow in Hero Super Player 3000 allows remote atta…
- CVE-2008-7163Directory traversal vulnerability in mods/Integrated/index.p…
- CVE-2008-7164Multiple unspecified vulnerabilities in Shareaza before 2.3.…
- CVE-2008-7165Cross-site request forgery in cp06_wifi_m_nocifr.cgi in the …
- CVE-2008-7166Buffer overflow in the web interface in BitTorrent 6.0.1 (bu…
- CVE-2008-7167Unrestricted file upload vulnerability in upload.php in Page…
- CVE-2008-7169SQL injection vulnerability in Jabode horoscope extension (c…
- CVE-2008-7170GSC build 2067 and earlier relies on the client to enforce a…
- CVE-2008-7171Multiple cross-site scripting (XSS) vulnerabilities in Light…
- CVE-2008-7172Lightweight news portal (LNP) 1.0b does not properly restric…
- CVE-2008-7173The Jura Internet Connection Kit for the Jura Impressa F90 c…
- CVE-2008-7174Multiple buffer overflows in the Jura Internet Connection Ki…
Are you affected by CVE-2008-7168?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
