32990Third-party advisory
http://secunia.com/advisories/32990 CVE-2008-6496
Visagesoft eXPert PDF EditorX - 'VSPDFEditorX.ocx' Insecure Method
Record summary
CVE-2008-6496 has a selected CVSS score of 8.8; EIP currently links 1 catalogued exploit.
Description
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVisagesoft eXPert PDF EditorX - 'VSPDFEditorX.ocx' Insecure MethodExploitDB exploitby Marco TortiNot analyzed1 file
References
532664vdb entry
http://www.securityfocus.com/bid/32664 expertpdfeditorx-activex-file-overwrite(47166)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/47166 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6496 7358exploit
https://www.exploit-db.com/exploits/7358