6.8
CVSSv2

CVE-2007-3649

Published: 10/07/2007 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote malicious users to create or overwrite arbitrary files via the second argument to the SaveToFile method.

Vulnerable Product Search on Vulmon Subscribe to Product

hp photo digital imaging activex control 2.1.0.556

Exploits

<pre> <code><span style="font: 10pt Courier New;"><span class="general1-symbol">------------------------------------------------------------------------------- <b>HP Digital Imaging (hpqvwocxdll v 210556) "SaveToFile()" Insecure Method</b> url: wwwhpcom/ author: shinnai mail: shinnai[at]autisti ...