CVE-2008-4493
Microsoft Digital Image - Improper Input Validation
Title source: ruleDescription
Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Nine:Situations:Group · htmlremotewindows
https://www.exploit-db.com/exploits/6699
References (5)
Scores
EPSS
0.4214
EPSS Percentile
97.5%
Details
CWE
CWE-20
Status
published
Products (1)
microsoft/digital_image
2006 unknown
Published
Oct 08, 2008
Tracked Since
Feb 18, 2026