9.3
CVSSv2

CVE-2008-4342

Published: 30/09/2008 Updated: 14/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and previous versions, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote malicious users to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

Vulnerable Product Search on Vulmon Subscribe to Product

burnaware technologies burnaware 2.1.3

numedia soft numedia dvd burning sdk 1.008

impressum cdburnerxp 4.2.1.976

Exploits

<!-- 506 19/09/2008 ----------------------------------------------------------- -- NuMedia Soft NMS DVD Burning SDK Activex (NMSDVDXdll) remote exploit -- by Nine:Situations:Group::bruiser software site: wwwnugroovzcom/ our site: retrogodaltervistaorg/ affected software: CDBurnerXP 421976, ?? tested against IE6 setting ...