// For flags

CVE-2009-2011

Worldweaver DX Studio Player 3.0.29 - 'shell.execute()' Command Execution

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

4
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method.

Worldweaver DX Studio Player v3.0.29.0, v3.0.22.0, v3.0.12.0, y probablemente otras versiones anteriores a la v3.0.29.1, cuando es utilizado como plug-in de Firefox, no restringe el acceso al metodo shell.execute JavaScript API, lo que permite a atacantes remotos ejecutar comandos arbitrarios a través de el fichero .dxstudio que invoca este método.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-06-08 CVE Reserved
  • 2009-06-10 CVE Published
  • 2010-05-26 First Exploit
  • 2024-08-05 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dxstudio
Search vendor "Dxstudio"
Dx Studio Player
Search vendor "Dxstudio" for product "Dx Studio Player"
<= 3.0.29.0
Search vendor "Dxstudio" for product "Dx Studio Player" and version " <= 3.0.29.0"
-
Affected
in Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
*-
Safe
Dxstudio
Search vendor "Dxstudio"
Dx Studio Player
Search vendor "Dxstudio" for product "Dx Studio Player"
3.0.12.0
Search vendor "Dxstudio" for product "Dx Studio Player" and version "3.0.12.0"
-
Affected
in Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
*-
Safe
Dxstudio
Search vendor "Dxstudio"
Dx Studio Player
Search vendor "Dxstudio" for product "Dx Studio Player"
3.0.22.0
Search vendor "Dxstudio" for product "Dx Studio Player" and version "3.0.22.0"
-
Affected
in Mozilla
Search vendor "Mozilla"
Firefox
Search vendor "Mozilla" for product "Firefox"
*-
Safe