peter bassill · operator
$ cve CVE-2008-6496 JSON

CVE-2008-6496 EXPLOIT

8.8
HIGH · CVSS 2.0 · EPSS 2.7% (pctl 85)

Patch early

A public exploit exists.

Description

Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.

Scoring

CVSS8.8 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:C/A:C
EPSS2.69% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-03-20
Last modified2026-06-16

Affected (1)

VendorProduct
visagesoftexpert pdf editorx

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD