9.3
CVE-2008-2683
- EPSS 34.76%
- Veröffentlicht 12.06.2008 12:21:00
- Zuletzt bearbeitet 16.06.2026 22:54:13
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, and the local filename in the second argument. NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Black Ice ≫ Barcode Sdk Version5.01
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 34.76% | 0.982 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://secunia.com/advisories/30548
http://securityreason.com/securityalert/8276
http://securityreason.com/securityalert/8277
http://www.exploit-db.com/exploits/17415
http://www.osvdb.org/46007
http://www.vupen.com/english/advisories/2008/1768/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/42891
https://www.exploit-db.com/exploits/5750