[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-0189Date: (C)2010-02-23   (M)2023-12-22


A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1023651
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856
BID-38313
SECUNIA-38729
OSVDB-62547
ADV-2010-0459
adobe-dlmanager-unspecified-file-download(56370)
http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx
http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html
http://blogs.zdnet.com/security/?p=5505
http://www.adobe.com/support/security/bulletins/apsb10-08.html
http://www.akitasecurity.nl/advisory.php?id=AK20090401
oval:org.mitre.oval:def:7182

CPE    1
cpe:/a:adobe:download_manager
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:10002
oval:org.mitre.oval:def:7182

© SecPod Technologies