CVE-2008-4549

ImageShack Toolbar 4.5.7 - Arbitrary File Upload via BuildSlideShow Method

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4549. PoCs published by rgod.

AI-analyzed exploit summary This exploit demonstrates an insecure method in the ImageShack Toolbar 4.5.7 FileUploader Class (ImageShackToolbar.dll) that allows arbitrary file uploads from a user's local system to ImageShack's servers via a malicious webpage. The PoC uses VBScript to invoke the vulnerable COM object and upload files, bypassing intended restrictions.

Description

The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlideShow method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · htmlremotewindows
https://www.exploit-db.com/exploits/4981

This exploit demonstrates an insecure method in the ImageShack Toolbar 4.5.7 FileUploader Class (ImageShackToolbar.dll) that allows arbitrary file uploads from a user's local system to ImageShack's servers via a malicious webpage. The PoC uses VBScript to invoke the vulnerable COM object and upload files, bypassing intended restrictions.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: ImageShack Toolbar 4.5.7
No auth needed
Prerequisites: Victim must have ImageShack Toolbar 4.5.7 installed · Victim must visit a malicious webpage hosting the exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/40628
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4981
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28644
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4410
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/486941/100/200/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27439
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39921

Scores

EPSS 0.0662
EPSS Percentile 93.0%

Details

CWE
CWE-20
Status published
Products (2)
imageshack/imageshack_toolbar 4.5.7
imageshack/imageshack_toolbar 4.5.7.69
Published Oct 14, 2008
Tracked Since Feb 18, 2026