← All CVEs

CVE-2008-4453

high · 9.3

The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

9.3
CVSS
10.5%
EPSS (exploit prob.)
96th
EPSS percentile
2008-10-06
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
dspicturelight_imaging_toolkit4.7.1
dspicturepro_imaging_sdk5.7.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-4453