9.3
CVSSv2

CVE-2010-3749

Published: 19/10/2010 Updated: 26/01/2011
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The browser-plugin implementation in RealNetworks RealPlayer 11.0 up to and including 11.1 and RealPlayer SP 1.0 up to and including 1.1 allows remote malicious users to arguments to the RecordClip method, which allows remote malicious users to download an arbitrary program onto a client machine, and execute this program, via a " (double quote) in an argument to the RecordClip method, aka "parameter injection."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 11.1

realnetworks realplayer 11.0

realnetworks realplayer 11.0.1

realnetworks realplayer 11.0.4

realnetworks realplayer 11.0.5

realnetworks realplayer 11.0.2

realnetworks realplayer 11.0.3

realnetworks realplayer sp 1.0.1

realnetworks realplayer sp 1.0.0

realnetworks realplayer sp 1.1.3

realnetworks realplayer sp 1.1.4

realnetworks realplayer sp 1.1.1

realnetworks realplayer sp 1.1.2

realnetworks realplayer sp 1.0.2

realnetworks realplayer sp 1.0.5

realnetworks realplayer sp 1.1

Exploits

Sources: wwwsecurityfocuscom/bid/44443/info packetstormsecurityorg/files/view/97522/recordingmanager-ietxt <html> <p> Written by Sean de Regge (seanderegge hotmailcom) Exploit for the parameter injection bug in Realplayers RecordClip() activeX function and firefox plugin wwwzerodayinitiativecom/a ...