[Forgot Password]
Login  Register Subscribe

24003

 
 

131573

 
 

108566

 
 

909

 
 

85401

 
 

134

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2010-0189Date: (C)2010-02-23   (M)2018-03-27


A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : CVSS Score : 9.3
Exploit Score: Exploit Score: 8.6
Impact Score: Impact Score: 10.0
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: NETWORK
Attack Complexity: Access Complexity: MEDIUM
Privileges Required: Authentication: NONE
User Interaction: Confidentiality: COMPLETE
Scope: Integrity: COMPLETE
Confidentiality: Availability: COMPLETE
Integrity:  
Availability:  
  
Reference:
SECTRACK-1023651
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856
BID-38313
SECUNIA-38729
OSVDB-62547
ADV-2010-0459
IAVM:2010-B-0015
adobe-dlmanager-unspecified-file-download(56370)
http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx
http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html
http://blogs.zdnet.com/security/?p=5505
http://www.adobe.com/support/security/bulletins/apsb10-08.html
http://www.akitasecurity.nl/advisory.php?id=AK20090401

CPE    1
cpe:/a:adobe:download_manager:1.6.2.60
CWE    1
CWE-20
OVAL    2
oval:org.mitre.oval:def:7182
oval:org.secpod.oval:def:10002

© SecPod Technologies