Vulnerabilities > CVE-2008-4924 - Arbitrary File Overwrite vulnerability in MW6 Technologies 1D Barcode Decoder Activex 3.0.0.1

047910
CVSS 9.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
mw6-technologies
critical
exploit available

Summary

Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

Vulnerable Configurations

Part Description Count
Application
Mw6_Technologies
1

Exploit-Db

descriptionMW6 Barcode ActiveX (Barcode.dll) Insecure Method Exploit. CVE-2008-4924. Remote exploit for windows platform
fileexploits/windows/remote/6871.html
idEDB-ID:6871
last seen2016-02-01
modified2008-10-29
platformwindows
port
published2008-10-29
reporterDeltahackingTEAM
sourcehttps://www.exploit-db.com/download/6871/
titleMW6 Barcode ActiveX Barcode.dll Insecure Method Exploit
typeremote