CVE-2008-6496
VISAGESOFT eXPert PDF EditorX 1.0.200.0 - Arbitrary File Write via extractPagesToFile
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6496. PoCs published by Marco Torti.
AI-analyzed exploit summary This exploit targets an insecure method in VISAGESOFT eXPert PDF EditorX (VSPDFEditorX.ocx) that allows arbitrary file overwrite via the 'extractPagesToFile' method. The PoC demonstrates file overwrite by saving a file to 'c:\windows\-system.ini' when a button is clicked in a web page.
Description
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.
Exploits (1)
This exploit targets an insecure method in VISAGESOFT eXPert PDF EditorX (VSPDFEditorX.ocx) that allows arbitrary file overwrite via the 'extractPagesToFile' method. The PoC demonstrates file overwrite by saving a file to 'c:\windows\-system.ini' when a button is clicked in a web page.