peter bassill · operator
$ cve CVE-2008-3156 JSON

CVE-2008-3156 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 4.1% (pctl 90)

Patch early

A public exploit exists.

Description

The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS4.07% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2008-07-11
Last modified2026-06-16

Affected (1)

VendorProduct
pandapanda activescan

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD