CVE-2008-4549
Estado: ModificadaBaja (2.6)—
The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlideShow method.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.62%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://osvdb.org/40628
- http://secunia.com/advisories/28644
- http://securityreason.com/securityalert/4410
- http://www.securityfocus.com/archive/1/486941/100/200/threaded
- http://www.securityfocus.com/bid/27439
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39921
- https://www.exploit-db.com/exploits/4981
- http://osvdb.org/40628
- http://secunia.com/advisories/28644
- http://securityreason.com/securityalert/4410
- http://www.securityfocus.com/archive/1/486941/100/200/threaded
- http://www.securityfocus.com/bid/27439
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39921
- https://www.exploit-db.com/exploits/4981
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4549",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-10-14T18:12:14.333",
"references": [
{
"url": "http://osvdb.org/40628",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28644",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/4410",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/486941/100/200/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27439",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39921",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/4981",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/40628",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28644",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/4410",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/486941/100/200/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27439",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/39921",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/4981",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The ImageShack Toolbar ActiveX control (ImageShackToolbar.dll) in ImageShack Toolbar 4.5.7, possibly including 4.5.7.69, allows remote attackers to force the upload of arbitrary image files to the ImageShack site via a file: URI argument to the BuildSlideShow method."
},
{
"lang": "es",
"value": "El control ActiveX ImageShack Toolbar (ImageShackToolbar.dll) en ImageShack Toolbar v4.5.7, posiblemente incluyendo v4.5.7.69, permite a atacantes remotos forzar la subida de ficheros de imagen de su elección al sitio ImageShack a través de un fichero: argumento URI del método BuildSlideShow."
}
],
"lastModified": "2026-06-16T22:58:03.210",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imageshack:imageshack_toolbar:4.5.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2AB8AAB2-3EE6-472E-8E86-C2D27924C2C4"
},
{
"criteria": "cpe:2.3:a:imageshack:imageshack_toolbar:4.5.7.69:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88950017-BEDE-4A92-96CA-EE53176F0B72"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}