Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4493

Опубликовано: 08 окт. 2008
Источник: nvd
CVSS2: 6.8
EPSS Средний

Описание

Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:digital_image:2006:unknown:starter:*:*:*:*:*

EPSS

Процентиль: 97%
0.42139
Средний

6.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

github
почти 4 года назад

Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.

EPSS

Процентиль: 97%
0.42139
Средний

6.8 Medium

CVSS2

Дефекты

CWE-20