Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.
References
Link | Resource |
---|---|
http://secunia.com/advisories/35764 | Vendor Advisory |
http://www.vupen.com/english/advisories/2009/1834 | Vendor Advisory |
http://www.coresecurity.com/content/winds3d-viewer-advisory | Exploit |
http://www.securityfocus.com/bid/35595 | Exploit |
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-07-10 08:30
Updated : 2009-07-12 21:00
NVD link : CVE-2009-2386
Mitre link : CVE-2009-2386
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
awingsoft
- awakening_winds3d_viewer_plugin