CVE-2009-1792
Summary
| CVE | CVE-2009-1792 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-05-29 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the sURL argument). |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | All | All | All | All |
| Application | Stonetrip | S3dplayer Standalone | 1.6.2.4 | All | All | All |
| Application | Stonetrip | S3dplayer Standalone | 1.7.0.1 | All | All | All |
| Application | Stonetrip | S3dplayer Web | 1.6.0.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Ston3D "system.openURL()" Command Injection Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Ston3D S3DPlayer Web and Standalone 'system.openURL()' Remote Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Core Security Technologies | af854a3a-2127-422b-91ae-364da2661108 | www.coresecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.