CVE-2008-4919
VISAGESOFT eXPert PDF Viewer X ActiveX 3.0.990.0 - Arbitrary File Write via savePageAsBitmap Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4919. PoCs published by Marco Torti.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file overwrite vulnerability in VISAGESOFT eXPertPDFViewerX (VSPDFViewerX.ocx) via the insecure 'savePageAsBitmap' method. The PoC uses VBScript to trigger the method and overwrite a system file.
Description
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method.
Exploits (1)
This exploit demonstrates an arbitrary file overwrite vulnerability in VISAGESOFT eXPertPDFViewerX (VSPDFViewerX.ocx) via the insecure 'savePageAsBitmap' method. The PoC uses VBScript to trigger the method and overwrite a system file.