Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request.  NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
                
            Metrics
Affected Vendors & Products
Advisories
    No advisories yet.
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T10:17:09.749Z
Reserved: 2008-10-08T00:00:00
Link: CVE-2008-4493
No data.
Status : Deferred
Published: 2008-10-08T22:00:02.013
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-4493
No data.
                        OpenCVE Enrichment
                    No data.