peter bassill · operator
$ cve CVE-2008-4493 JSON

CVE-2008-4493 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 17.6% (pctl 97)

Patch early

A public exploit exists.

Description

Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS17.59% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2008-10-08
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftdigital image

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD