CVE-2008-2283
Idautomation Aztec Barcode - Improper Input Validation
Title source: ruleDescription
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL (aka IDautomation Datamatrix Barcode) 1.6.0.6, (c) the IDAuto.PDF417.1 ActiveX control in IDAutomationPDF417_6.dll (aka IDautomation PDF417 Barcode) 1.6.0.6, and (d) the IDAuto.Aztec.1 ActiveX control in IDAutomationAZTEC.dll (aka IDautomation Aztec Barcode) 1.7.1.0.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/5612
References (5)
Scores
EPSS
0.0568
EPSS Percentile
90.4%
Details
CWE
CWE-20
Status
published
Products (4)
idautomation/aztec_barcode
1.7.1.0
idautomation/datamatrix_barcode
1.6.0.6
idautomation/linear_barcode
1.6.0.6
idautomation/pdf417_barcode
1.6.0.6
Published
May 18, 2008
Tracked Since
Feb 18, 2026