Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4342
Description:NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.
Test IDs: 1.3.6.1.4.1.25623.1.0.900132  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4342
BugTraq ID: 31374
http://www.securityfocus.com/bid/31374
Bugtraq: 20081027 Blaze Media Pro 8.02 SE vulnerability (Google Search)
http://www.securityfocus.com/archive/1/497831/100/0/threaded
https://www.exploit-db.com/exploits/6491
http://retrogod.altervista.org/9sg_numedia_xpl.html
http://www.shinnai.net/xplits/TXT_TrWE9AJA8nQpuFsnxBcq
http://secunia.com/advisories/31936
http://secunia.com/advisories/31949
http://secunia.com/advisories/31950
http://secunia.com/advisories/32455
http://www.vupen.com/english/advisories/2008/2663
XForce ISS Database: nmsdvdburning-nmsdvdx-file-overwrite(45330)
https://exchange.xforce.ibmcloud.com/vulnerabilities/45330




© 1998-2025 E-Soft Inc. All rights reserved.