Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method.Referenceshttp://osvdb.org/37675https://exchange.xforce.ibmcloud.com/vulnerabilities/35124http://securityreason.com/securityalert/2846http://www.securityfocus.com/archive/1/472384/100/0/threadedhttp://secunia.com/advisories/25869https://www.exploit-db.com/exploits/4119