Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.
References
Configurations
Information
Published : 2007-06-29 11:30
Updated : 2018-10-16 09:50
NVD link : CVE-2007-3487
Mitre link : CVE-2007-3487
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
hp
- photo_digital_imaging_activex_control