CVE-2008-6496 EXPLOIT
8.8
HIGH · CVSS 2.0 · EPSS 2.7% (pctl 85)
Patch early
A public exploit exists.
Description
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.
Scoring
| CVSS | 8.8 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:C/A:C |
| EPSS | 2.69% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-03-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| visagesoft | expert pdf editorx |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Visagesoft eXPert PDF EditorX - 'VSPDFEditorX.ocx' Insecure Method | 2008-12-05 |
References
- http://secunia.com/advisories/32990
- http://www.securityfocus.com/bid/32664
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47166
- https://www.exploit-db.com/exploits/7358
- http://secunia.com/advisories/32990
- http://www.securityfocus.com/bid/32664
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47166
- https://www.exploit-db.com/exploits/7358
→ the Explorer · watch your stack · NVD