CVE-2008-2683

Scores

EPSS

0.794medium79.4%
0%20%40%60%80%100%

Percentile: 79.4%

CVSS

9.3critical2.0
0246810

CVSS Score: 9.3/10

All CVSS Scores

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, and the local filename in the second argument. NOTE: some of these details are obtained from third party information.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-20

Exploits

Exploit ID: 17415

Source: exploitdb

URL: https://www.exploit-db.com/exploits/17415

Exploit ID: 17424

Source: exploitdb

URL: https://www.exploit-db.com/exploits/17424

Exploit ID: 5750

Source: exploitdb

URL: https://www.exploit-db.com/exploits/5750

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: barcode_sdk

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:black_ice:barcode_sdk:5.01:*:*:*:*:*:*:*",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list