peter bassill · operator
$ cve CVE-2007-5320 JSON

CVE-2007-5320 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 6.5% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:N/I:P/A:P
EPSS6.51% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2007-10-09
Last modified2026-06-16

Affected (1)

VendorProduct
pegasus imagingimagxpress

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD