[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

112965

 
 

909

 
 

87888

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2010-0189Date: (C)2010-02-23   (M)2018-03-27


A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1023651
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856
BID-38313
SECUNIA-38729
OSVDB-62547
ADV-2010-0459
IAVM:2010-B-0015
adobe-dlmanager-unspecified-file-download(56370)
http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx
http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html
http://blogs.zdnet.com/security/?p=5505
http://www.adobe.com/support/security/bulletins/apsb10-08.html
http://www.akitasecurity.nl/advisory.php?id=AK20090401

CPE    1
cpe:/a:adobe:download_manager:1.6.2.60
CWE    1
CWE-20
OVAL    2
oval:org.secpod.oval:def:10002
oval:org.mitre.oval:def:7182

© SecPod Technologies