9.3
CVSSv2

CVE-2008-4728

Published: 24/10/2008 Updated: 14/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 945
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote malicious users to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method. NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.

Vulnerable Product Search on Vulmon Subscribe to Product

hummingbird deployment wizard 2008

Exploits

-------------------------------------------------------------------------------- Hummingbird Deployment Wizard 2008 (DeployRundll) Arbitrary File Execution(2) url: wwwhummingbirdcom Author: shinnai mail: shinnai[at]autistici[dot]org site: wwwshinnainet This was written for educational purpose Use it at your own risk Au ...
------------------------------------------------------------------------------------ Hummingbird Deployment Wizard 2008 (DeployRundll) Registry Values Creation/Change url: wwwhummingbirdcom Author: shinnai mail: shinnai[at]autistici[dot]org site: wwwshinnainet This was written for educational purpose Use it at your own r ...
------------------------------------------------------------------------------ Hummingbird Deployment Wizard 2008 (DeployRundll) Arbitrary File Execution url: wwwhummingbirdcom Author: shinnai mail: shinnai[at]autistici[dot]org site: wwwshinnainet This was written for educational purpose Use it at your own risk Author ...