{"api_version":"1","generated_at":"2026-07-23T12:22:25+00:00","cve":"CVE-2008-1116","urls":{"html":"https://cve.report/CVE-2008-1116","api":"https://cve.report/api/cve/CVE-2008-1116.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-1116","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-1116"},"summary":{"title":"CVE-2008-1116","description":"Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-03-03 18:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/5188","name":"https://www.exploit-db.com/exploits/5188","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Rising AntiVirus Online Scanner - Insecure Method Flaw - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0683/references","name":"http://www.vupen.com/english/advisories/2008/0683/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27997","name":"http://www.securityfocus.com/bid/27997","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Rising Web Scan Object 'OL2005.dll' ActiveX Control Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/29109","name":"http://secunia.com/advisories/29109","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Rising Online Virus Scanner Web Scan ActiveX Control \"UpdateEngine()\" Insecure Method - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40838","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40838","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-1116","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1116","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rising_antivirus_international","cpe5":"rising_web_scan_object","cpe6":"18.0.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:08:57.605Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27997","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27997"},{"name":"risingonline-webscan-code-execution(40838)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40838"},{"name":"ADV-2008-0683","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0683/references"},{"name":"29109","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29109"},{"name":"5188","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/5188"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-02-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27997","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27997"},{"name":"risingonline-webscan-code-execution(40838)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40838"},{"name":"ADV-2008-0683","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0683/references"},{"name":"29109","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29109"},{"name":"5188","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/5188"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-1116","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27997","refsource":"BID","url":"http://www.securityfocus.com/bid/27997"},{"name":"risingonline-webscan-code-execution(40838)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40838"},{"name":"ADV-2008-0683","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0683/references"},{"name":"29109","refsource":"SECUNIA","url":"http://secunia.com/advisories/29109"},{"name":"5188","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/5188"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-1116","datePublished":"2008-03-03T18:00:00.000Z","dateReserved":"2008-03-03T00:00:00.000Z","dateUpdated":"2024-08-07T08:08:57.605Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-03-03 18:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rising_antivirus_international:rising_web_scan_object:18.0.7:*:*:*:*:*:*:*","matchCriteriaId":"B44E1BDE-E6E8-4805-8475-C39FC08F6B26"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"1116","Ordinal":"1","Title":"CVE-2008-1116","CVE":"CVE-2008-1116","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"1116","Ordinal":"1","NoteData":"Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2008-1116"},{"CveYear":"2008","CveId":"1116","Ordinal":"2","NoteData":"2008-03-03","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"1116","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}