PoC Index

CVE-2007-5320

MEDIUM 4.0EPSS 6.5%

Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).

CVSS v2.0
4.0 MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
EPSS
6.51% chance of exploitation in the next 30 days, 93th percentile
Published
2007-10-09
Updated
2024-08-07

ExploitDB entries (1)

References

Related