9.3
CVSSv2

CVE-2009-2386

Published: 10/07/2009 Updated: 13/07/2009
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote malicious users to force the download and execution of arbitrary files via the GetURL method.

Vulnerable Product Search on Vulmon Subscribe to Product

awingsoft awakening winds3d viewer plugin 3.5.0.0

awingsoft awakening winds3d viewer plugin 3.0.0.5

Exploits

source: wwwsecurityfocuscom/bid/35595/info Winds3D Viewer is prone to a vulnerability that can allow malicious files to be downloaded an executed within the context of the affected browser that uses the plugin Successfully exploiting this issue will allow attackers to compromise the affected application that uses the plugin Winds3D Vi ...