2.6

CVE-2008-4549

The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlideShow method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ImageshackImageshack Toolbar Version4.5.7
ImageshackImageshack Toolbar Version4.5.7.69
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.62% 0.93
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://osvdb.org/40628
http://secunia.com/advisories/28644
Vendor Advisory
http://securityreason.com/securityalert/4410
http://www.securityfocus.com/archive/1/486941/100/200/threaded
http://www.securityfocus.com/bid/27439
https://exchange.xforce.ibmcloud.com/vulnerabilities/39921
https://www.exploit-db.com/exploits/4981