peter bassill · operator
$ cve CVE-2008-4749 JSON

CVE-2008-4749 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS3.03% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2008-10-27
Last modified2026-06-16

Affected (1)

VendorProduct
db soft labvimp x

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD