Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.
References
Link | Resource |
---|---|
http://secunia.com/advisories/35764 | Vendor Advisory |
http://www.coresecurity.com/content/winds3d-viewer-advisory | Exploit |
http://www.securityfocus.com/bid/35595 | Exploit |
http://www.vupen.com/english/advisories/2009/1834 | Vendor Advisory |
http://secunia.com/advisories/35764 | Vendor Advisory |
http://www.coresecurity.com/content/winds3d-viewer-advisory | Exploit |
http://www.securityfocus.com/bid/35595 | Exploit |
http://www.vupen.com/english/advisories/2009/1834 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/35764 - Vendor Advisory | |
References | () http://www.coresecurity.com/content/winds3d-viewer-advisory - Exploit | |
References | () http://www.securityfocus.com/bid/35595 - Exploit | |
References | () http://www.vupen.com/english/advisories/2009/1834 - Vendor Advisory |
Information
Published : 2009-07-10 15:30
Updated : 2025-04-09 00:30
NVD link : CVE-2009-2386
Mitre link : CVE-2009-2386
CVE.ORG link : CVE-2009-2386
JSON object : View
Products Affected
awingsoft
- awakening_winds3d_viewer_plugin
CWE
CWE-20
Improper Input Validation