{"api_version":"1","generated_at":"2026-07-23T10:00:50+00:00","cve":"CVE-2009-1792","urls":{"html":"https://cve.report/CVE-2009-1792","api":"https://cve.report/api/cve/CVE-2009-1792.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1792","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1792"},"summary":{"title":"CVE-2009-1792","description":"The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the sURL argument).","state":"PUBLISHED","assigner":"mitre","published_at":"2009-05-29 18:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-78","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/503887/100/0/threaded","name":"http://www.securityfocus.com/archive/1/503887/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35256","name":"http://secunia.com/advisories/35256","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ston3D \"system.openURL()\" Command Injection Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35105","name":"http://www.securityfocus.com/bid/35105","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ston3D S3DPlayer Web and Standalone 'system.openURL()' Remote Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.coresecurity.com/content/StoneTrip-S3DPlayers","name":"http://www.coresecurity.com/content/StoneTrip-S3DPlayers","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Core Security Technologies","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1792","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1792","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1792","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1792","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stonetrip","cpe5":"s3dplayer_standalone","cpe6":"1.6.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1792","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stonetrip","cpe5":"s3dplayer_standalone","cpe6":"1.7.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"1792","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"stonetrip","cpe5":"s3dplayer_web","cpe6":"1.6.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:27:54.450Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35105","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35105"},{"name":"35256","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35256"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.coresecurity.com/content/StoneTrip-S3DPlayers"},{"name":"20090528 CORE-2009-0401 - StoneTrip S3DPlayers remote command injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/503887/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-05-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the sURL argument)."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"35105","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35105"},{"name":"35256","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35256"},{"tags":["x_refsource_MISC"],"url":"http://www.coresecurity.com/content/StoneTrip-S3DPlayers"},{"name":"20090528 CORE-2009-0401 - StoneTrip S3DPlayers remote command injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/503887/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1792","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the sURL argument)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35105","refsource":"BID","url":"http://www.securityfocus.com/bid/35105"},{"name":"35256","refsource":"SECUNIA","url":"http://secunia.com/advisories/35256"},{"name":"http://www.coresecurity.com/content/StoneTrip-S3DPlayers","refsource":"MISC","url":"http://www.coresecurity.com/content/StoneTrip-S3DPlayers"},{"name":"20090528 CORE-2009-0401 - StoneTrip S3DPlayers remote command injection","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/503887/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1792","datePublished":"2009-05-29T18:00:00.000Z","dateReserved":"2009-05-26T00:00:00.000Z","dateUpdated":"2024-08-07T05:27:54.450Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-05-29 18:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-78","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:stonetrip:s3dplayer_standalone:1.6.2.4:*:*:*:*:*:*:*","matchCriteriaId":"52C5D62C-CCD9-44A1-B120-15B462A14802"},{"vulnerable":true,"criteria":"cpe:2.3:a:stonetrip:s3dplayer_standalone:1.7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"A8FBC588-1328-47C7-8F41-33C969FF6373"},{"vulnerable":true,"criteria":"cpe:2.3:a:stonetrip:s3dplayer_web:1.6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B41CBD9C-064D-41C0-9FDE-E1A6C4278A06"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*","matchCriteriaId":"2CF61F35-5905-4BA9-AD7E-7DB261D2F256"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:stonetrip:s3dplayer_standalone:1.6.2.4:*:*:*:*:*:*:*","matchCriteriaId":"52C5D62C-CCD9-44A1-B120-15B462A14802"},{"vulnerable":true,"criteria":"cpe:2.3:a:stonetrip:s3dplayer_web:1.6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"B41CBD9C-064D-41C0-9FDE-E1A6C4278A06"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","matchCriteriaId":"4C56F007-5F8E-4BDD-A803-C907BCC0AF55"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","matchCriteriaId":"155AD4FB-E527-4103-BCEF-801B653DEA37"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:stonetrip:s3dplayer_standalone:1.6.2.4:*:*:*:*:*:*:*","matchCriteriaId":"52C5D62C-CCD9-44A1-B120-15B462A14802"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1792","Ordinal":"1","Title":"CVE-2009-1792","CVE":"CVE-2009-1792","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1792","Ordinal":"1","NoteData":"The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the sURL argument).","Type":"Description","Title":"CVE-2009-1792"},{"CveYear":"2009","CveId":"1792","Ordinal":"2","NoteData":"2009-05-29","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1792","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}