CVE-2008-4493 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 17.6% (pctl 97)
Patch early
A public exploit exists.
Description
Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 17.59% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-10-08 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | digital image |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft PicturePusher - ActiveX Cross-Site Arbitrary File Upload | 2008-10-08 |
References
- http://securityreason.com/securityalert/4376
- http://www.securityfocus.com/bid/31632
- http://www.securitytracker.com/id?1021018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45735
- https://www.exploit-db.com/exploits/6699
- http://securityreason.com/securityalert/4376
- http://www.securityfocus.com/bid/31632
- http://www.securitytracker.com/id?1021018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45735
- https://www.exploit-db.com/exploits/6699
→ the Explorer · watch your stack · NVD