Vulnerabilities > CVE-2007-3649 - Unspecified vulnerability in HP Photo Digital Imaging Activex Control 2.1.0.556

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
hp
exploit available

Summary

Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method.

Vulnerable Configurations

Part Description Count
Application
Hp
1

Exploit-Db

descriptionHP Digital Imaging (hpqvwocx.dll v. 2.1.0.556) SaveToFile() Exploit. CVE-2007-3649. Remote exploit for windows platform
fileexploits/windows/remote/4155.html
idEDB-ID:4155
last seen2016-01-31
modified2007-07-06
platformwindows
port
published2007-07-06
reportershinnai
sourcehttps://www.exploit-db.com/download/4155/
titleHP Digital Imaging hpqvwocx.dll 2.1.0.556 - SaveToFile Exploit
typeremote