9.3
CVSSv2

CVE-2009-2011

Published: 16/06/2009 Updated: 14/02/2024
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions prior to 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote malicious users to execute arbitrary commands via a .dxstudio file that invokes this method.

Vulnerable Product Search on Vulmon Subscribe to Product

dxstudio dx_studio_player

dxstudio dx_studio_player 3.0.12.0

dxstudio dx_studio_player 3.0.22.0

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ DX Studio Player Firefox plug-in command injection 1 *Advisory Information* Title: DX Studio Player Firefox plug-in command injection Advisory ID: CORE-2009-0521 Advisory URL: wwwcore ...
## # $Id: dxstudio_player_execrb 9375 2010-05-26 22:39:56Z jduck $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' re ...