CVE-2007-5320
Pegasus Imaging ImagXpress 8.0 - Arbitrary File Overwrite
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).
Múltiples vulnerabilidades de salto de directorio absoluto en Pegasus Imaging ImagXpress 8.0 permite a atacantes remotos (1) borrar ficheros de su elección mediante el atributo CacheFile en el control ActiveX ThumbnailXpres.1 (PegasusImaging.ActiveX.ThumnailXpress1.dll) o (2) sobrescribir ficheros de su elección mediante la función CompactFile en el control ActiveX ImagXpress.8 (PegasusImaging.ActiveX.ImagXpress8.dll).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-10-05 First Exploit
- 2007-10-09 CVE Reserved
- 2007-10-09 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://osvdb.org/37959 | Vdb Entry | |
http://osvdb.org/37960 | Vdb Entry | |
http://www.securityfocus.com/bid/25949 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/3388 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/37012 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/4488 | 2007-10-05 | |
http://shinnai.altervista.org/exploits/txt/TXT_3DQ1nIkI6zmWCek4zP5U.html | 2024-08-07 | |
http://shinnai.altervista.org/exploits/txt/TXT_wfv7ZG0G6KnQlk1SieLd.html | 2024-08-07 | |
http://www.securityfocus.com/bid/25948 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27095 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pegasus Imaging Search vendor "Pegasus Imaging" | Imagxpress Search vendor "Pegasus Imaging" for product "Imagxpress" | 8.0 Search vendor "Pegasus Imaging" for product "Imagxpress" and version "8.0" | - |
Affected
|