6.4
CVSSv2

CVE-2007-3487

Published: 29/06/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote malicious users to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.

Vulnerable Product Search on Vulmon Subscribe to Product

hp photo digital imaging activex control 2.0.0.133

Exploits

: GOODFELLAS Security Research TEAM : : goodfellasshellcodecomar : <!-- hpqxmldll 200133 from HP Digital Imaging Arbitary Data Write =============================================== Internal ID: VULWAR200706275 Introduction hpqxmldll is a library included in the HP Photo Digital Imaging software package from the HP Company ...