Vulnerability Description
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ebay | Enhanced Picture Uploader Activex Control | <= 1.0.26 |
Related Weaknesses (CWE)
References
- http://osvdb.org/54968
- http://pages.ebay.com/securitycenter/activex/index.htmlVendor Advisory
- http://secunia.com/advisories/35412
- http://www.kb.cert.org/vuls/id/983731PatchUS Government Resource
- http://www.securityfocus.com/bid/35248
- http://osvdb.org/54968
- http://pages.ebay.com/securitycenter/activex/index.htmlVendor Advisory
- http://secunia.com/advisories/35412
- http://www.kb.cert.org/vuls/id/983731PatchUS Government Resource
- http://www.securityfocus.com/bid/35248
FAQ
What is CVE-2008-2475?
CVE-2008-2475 is a vulnerability with a CVSS score of 9.3 (HIGH). eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
How severe is CVE-2008-2475?
CVE-2008-2475 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-2475?
Check the references section above for vendor advisories and patch information. Affected products include: Ebay Enhanced Picture Uploader Activex Control.