CVE-2008-4749

critical

Description

Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.

References

https://www.exploit-db.com/exploits/6828

https://exchange.xforce.ibmcloud.com/vulnerabilities/46096

http://www.securityfocus.com/bid/31907

http://securityreason.com/securityalert/4509

Details

Source: Mitre, NVD

Published: 2008-10-27

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.02271