CVE-2007-3487

HP Photo Digital Imaging Activex Control - Path Traversal

Title source: rule

Description

Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by callAX · htmlremotewindows
https://www.exploit-db.com/exploits/4119

Scores

EPSS 0.1221
EPSS Percentile 93.9%

Details

CWE
CWE-22
Status published
Products (1)
hp/photo_digital_imaging_activex_control 2.0.0.133
Published Jun 29, 2007
Tracked Since Feb 18, 2026