{"api_version":"1","generated_at":"2026-07-23T14:48:44+00:00","cve":"CVE-2008-4749","urls":{"html":"https://cve.report/CVE-2008-4749","api":"https://cve.report/api/cve/CVE-2008-4749.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4749","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4749"},"summary":{"title":"CVE-2008-4749","description":"Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-10-27 20:00:04","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/6828","name":"https://www.exploit-db.com/exploits/6828","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46096","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46096","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/31907","name":"http://www.securityfocus.com/bid/31907","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"DB Software Laboratory 'VImpX.ocx' ActiveX Control Multiple File Corruption Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/4509","name":"http://securityreason.com/securityalert/4509","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"db Software Laboratory VImpX (VImpX.ocx) Multiple Vulnerabilities - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4749","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4749","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4749","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"db_soft_lab","cpe5":"vimp_x","cpe6":"4.8.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:24:21.048Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"db-activex-vimpx-file-overwrite(46096)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46096"},{"name":"4509","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4509"},{"name":"6828","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/6828"},{"name":"31907","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/31907"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-10-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"db-activex-vimpx-file-overwrite(46096)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46096"},{"name":"4509","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4509"},{"name":"6828","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/6828"},{"name":"31907","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/31907"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4749","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"db-activex-vimpx-file-overwrite(46096)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46096"},{"name":"4509","refsource":"SREASON","url":"http://securityreason.com/securityalert/4509"},{"name":"6828","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/6828"},{"name":"31907","refsource":"BID","url":"http://www.securityfocus.com/bid/31907"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4749","datePublished":"2008-10-27T19:00:00.000Z","dateReserved":"2008-10-27T00:00:00.000Z","dateUpdated":"2024-08-07T10:24:21.048Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-10-27 20:00:04","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:db_soft_lab:vimp_x:4.8.8.0:*:*:*:*:*:*:*","matchCriteriaId":"41764932-E1B7-4CA4-A947-37DFFE9FBFB6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4749","Ordinal":"1","Title":"CVE-2008-4749","CVE":"CVE-2008-4749","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4749","Ordinal":"1","NoteData":"Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, and (2) the SaveToFile method.","Type":"Description","Title":"CVE-2008-4749"},{"CveYear":"2008","CveId":"4749","Ordinal":"2","NoteData":"2008-10-27","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4749","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}