vendor:
PPLive
by:
Nine:Situations:Group::strawdog
7.5
CVSS
HIGH
URI Handler Remote Argument Injection
CWE
Product Name: PPLive
Affected Version From: PPLive <= 1.9.21
Affected Version To: PPLive <= 1.9.21
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2009
PPLive <= 1.9.21 uri handlers "/LoadModule" remote argument injection
The "synacast://", "Play://" ,"pplsv://" and "ppvod://" URI handlers in PPLive <= 1.9.21 do not verify certain parts of the URI before evaluating command line parameters. This can be exploited against Internet Explorer to e.g. load a dll from a remote UNC path via the "/LoadModule" parameter.
Mitigation:
Unknown