vendor:
Winds3D Player
by:
jduck
N/A
CVSS
N/A
Untrusted Program Execution
20
CWE
Product Name: Winds3D Player
Affected Version From: 3.5.0.9
Affected Version To: 3.5.0.9
Patch Exists: NO
Related CWE: CVE-2009-4850
CPE: a:awingsoft:winds3d_player
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2009
AwingSoft Winds3D Player 3.5 SceneURL Download and Execute
This module exploits an untrusted program execution vulnerability within the Winds3D Player from AwingSoft. The Winds3D Player is a browser plugin for IE (ActiveX), Opera (DLL) and Firefox (XPI). By setting the 'SceneURL' parameter to the URL to an executable, an attacker can execute arbitrary code. Testing was conducted using plugin version 3.5.0.9 for Firefox 3.5 and IE 8 on Windows XP SP3.
Mitigation:
No known mitigation or remediation for this vulnerability