The (1) Upsell.htm, (2) Main.html, and (3) Custsupport.html components in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.1.2 and 2.1.3 allow remote attackers to inject code into the RealOneActiveXObject process, and consequently bypass intended Local Machine Zone restrictions and load arbitrary ActiveX controls, via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2010-12-14 08:00
Updated : 2011-01-18 23:02
NVD link : CVE-2010-4388
Mitre link : CVE-2010-4388
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
realnetworks
- realplayer_sp
- realplayer