Vulnerabilities > CVE-2008-6638 - Configuration vulnerability in Versalsoft Http File Upload Activex Control 6.0.0.35

047910
CVSS 8.8 - HIGH
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
versalsoft
CWE-16
exploit available

Summary

Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method.

Vulnerable Configurations

Part Description Count
Application
Versalsoft
1

Common Weakness Enumeration (CWE)

Exploit-Db

  • idEDB-ID:5272
  • idEDB-ID:5569