CVE-2009-3735
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.
El control ActiveScan Installer ActiveX en as2stubie.dll anterior a v1.3.3.0 en PandaActiveScan Installer v2.0 y en Panda ActiveScan downloads software en un archivo as2guiie.cab ubicado en una URL cualquiera, y con la firma digital del archivo sin verificar antes de la instalación, permite a atacantes remotos ejecutar código de su elección a través de un argumento en una URL sobre un método sin especificar.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-10-22 CVE Reserved
- 2010-02-11 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/869993 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/MAPG-7QPKL3 | X_refsource_misc | |
http://www.securityfocus.com/bid/38067 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/38485 | 2018-10-12 | |
http://www.vupen.com/english/advisories/2010/0354 | 2018-10-12 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-008 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Panda Search vendor "Panda" | Panda Activescan Search vendor "Panda" for product "Panda Activescan" | 2.0 Search vendor "Panda" for product "Panda Activescan" and version "2.0" | - |
Affected
|