vendor:
DX Studio Player
by:
jduck
N/A
CVSS
N/A
Command Execution
78
CWE
Product Name: DX Studio Player
Affected Version From: 3.0.29.0
Affected Version To: 3.0.29.0
Patch Exists: YES
Related CWE: CVE-2009-2011, BID-35273, OSVDB-54969
CPE: a:worldweaver:dx_studio_player
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0191/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0192/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0195/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0197/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0196/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0193/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0109/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0058/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0168/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-4067/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1408/, https://www.rapid7.com/db/vulnerabilities/cisco-ios-cve-2011-1625/, https://www.rapid7.com/db/vulnerabilities/apache-tomcat-cve-2011-2481/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-2481/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0879/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0492/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0491/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0452/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0434/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1526/, https://www.rapid7.com/db/?q=CVE-2009-2011&type=&page=2, https://www.rapid7.com/db/?q=CVE-2009-2011&type=&page=3, https://www.rapid7.com/db/?q=CVE-2009-2011&type=&page=2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2009
Worldweaver DX Studio Player <= 3.0.29 shell.execute() Command Execution
This module exploits a command execution vulnerability within the DX Studio Player from Worldweaver. The player is a browser plugin for IE (ActiveX) and Firefox (dll). When an unsuspecting user visits a web page referring to a specially crafted .dxstudio document, an attacker can execute arbitrary commands.
Mitigation:
User should not visit any malicious web page