9.3
CVSSv2

CVE-2009-1087

Published: 25/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and previous versions allow remote malicious users to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

pplive pplive

pplive pplive 1.9.15

Exploits

-------------------------------------------------------------------------------- PPLive <= 1921 uri handlers "/LoadModule" remote argument injection by Nine:Situations:Group::strawdog -------------------------------------------------------------------------------- software site:wwwpplivecom/en/indexhtml our site: retrogodalte ...