CVE-2007-5320
Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or…
Does this matter?
Lower severity and a low EPSS score (6.51%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete arbitrary files via the CacheFile attribute in the ThumbnailXpres.1 ActiveX control (PegasusImaging.ActiveX.ThumnailXpress1.dll) or (2) overwrite arbitrary files via the CompactFile function in the ImagXpress.8 ActiveX control (PegasusImaging.ActiveX.ImagXpress8.dll).
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:H/Au:N/C:N/I:P/A:P
- EPSS
- 6.51% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- pegasus imaging/imagxpress
- Source
- cve@mitre.org
References
- http://osvdb.org/37959
- http://osvdb.org/37960
- http://secunia.com/advisories/27095Vendor Advisory
- http://shinnai.altervista.org/exploits/txt/TXT_3DQ1nIkI6zmWCek4zP5U.htmlExploit
- http://shinnai.altervista.org/exploits/txt/TXT_wfv7ZG0G6KnQlk1SieLd.htmlExploit
- http://www.securityfocus.com/bid/25948Exploit
- http://www.securityfocus.com/bid/25949
- http://www.vupen.com/english/advisories/2007/3388
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37012
- http://osvdb.org/37959
- http://osvdb.org/37960
- http://secunia.com/advisories/27095Vendor Advisory
- http://shinnai.altervista.org/exploits/txt/TXT_3DQ1nIkI6zmWCek4zP5U.htmlExploit
- http://shinnai.altervista.org/exploits/txt/TXT_wfv7ZG0G6KnQlk1SieLd.htmlExploit
- http://www.securityfocus.com/bid/25948Exploit
- http://www.securityfocus.com/bid/25949
- http://www.vupen.com/english/advisories/2007/3388
- https://exchange.xforce.ibmcloud.com/vulnerabilities/37012
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.