CVE-2007-5320
MEDIUM 4.0EPSS 6.5%
Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).
- CVSS v2.0
- 4.0 MEDIUM
AV:N/AC:H/Au:N/C:N/I:P/A:P - EPSS
- 6.51% chance of exploitation in the next 30 days, 93th percentile
- Published
- 2007-10-09
- Updated
- 2024-08-07