CVE-2008-2475: OS Command Injection
Published Jun 9, 2009
·Updated
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
Affected Software
1 affected component
eBay Enhanced Picture Uploader ActiveX control<=1.0.26
Remediation
Patch Available
Event History
Jun 9, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2475?
CVE-2008-2475 is considered critical due to its potential to allow remote code execution.
2
How do I fix CVE-2008-2475?
To fix CVE-2008-2475, update the eBay Enhanced Picture Uploader ActiveX control to version 1.0.27 or later.
3
Which versions are affected by CVE-2008-2475?
CVE-2008-2475 affects all versions of eBay Enhanced Picture Uploader ActiveX control before 1.0.27.
4
What type of threat does CVE-2008-2475 pose?
CVE-2008-2475 poses a threat by allowing attackers to execute arbitrary commands on the affected systems.
5
Is there a workaround for CVE-2008-2475?
A possible workaround for CVE-2008-2475 is to disable the use of the eBay Enhanced Picture Uploader ActiveX control until it can be updated.