9.3
CVSSv2

CVE-2009-4148

Published: 04/12/2009 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote malicious users to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4) .dsb file, as demonstrated by code that loads the WScript.Shell ActiveX control, related to a "script injection vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

daz3d daz studio 2.3.3.161

daz3d daz studio 2.3.3.163

daz3d daz studio 3.0.1.135

Exploits

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ DAZ Studio Arbitrary Command Execution 1 *Advisory Information* Title: DAZ Studio Arbitrary Command Execution Advisory Id: CORE-2009-0911 Advisory URL: wwwcoresecuritycom/content/dazstud ...