CVE-2010-0189
Summary
| CVE | CVE-2010-0189 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-23 20:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Download Manager | All | All | All | All |
| Application | Nos Microsystems | Getplus Download Manager | 1.5.2.35 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Adobe - Security Bulletins: APSB10-08 Security update available for Adobe Download Manager | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| getPlus insufficient domain name validation vulnerability - Security advisories - Akita Software Security | af854a3a-2127-422b-91ae-364da2661108 | www.akitasecurity.nl | |
| www.osvdb.org/62547 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Adobe Download Manager issue - Adobe Product Security Incident Response Team (PSIRT) | af854a3a-2127-422b-91ae-364da2661108 | blogs.adobe.com | |
| SecurityTracker.com Archives - Adobe Download Manager Flaw Lets Remote Users Download and Install Arbitrary Software | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Adobe getPlus DLM Unauthorised Installation Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Public Advisory: 02.23.10 // iDefense Labs | af854a3a-2127-422b-91ae-364da2661108 | labs.idefense.com | |
| Aviv Raff On .NET - Skeletons in Adobe's security closet | af854a3a-2127-422b-91ae-364da2661108 | aviv.raffon.net | |
| NOS getPlus Downloader Domain Validation Arbitrary File Download Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Skeletons in Adobe's security closet | ZDNet | af854a3a-2127-422b-91ae-364da2661108 | blogs.zdnet.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.