vendor:
HP Digital Imaging
by:
shinnai
7.5
CVSS
HIGH
Insecure Method
CWE
Product Name: HP Digital Imaging
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP2
2007
HP Digital Imaging (hpqvwocx.dll v. 2.1.0.556) “SaveToFile()” Insecure Method
This exploit overwrites the system.ini file, potentially causing the PC to not restart. It is a control marked as not safe for script or initialization, but implements object and data safety. It has been tested on Windows XP Professional SP2 with Internet Explorer 7.
Mitigation:
Make a backup of the system.ini file before running this exploit. Update to a patched version of the software.