{"api_version":"1","generated_at":"2026-07-23T11:36:00+00:00","cve":"CVE-2009-2386","urls":{"html":"https://cve.report/CVE-2009-2386","api":"https://cve.report/api/cve/CVE-2009-2386.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-2386","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-2386"},"summary":{"title":"CVE-2009-2386","description":"Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-07-10 15:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.coresecurity.com/content/winds3d-viewer-advisory","name":"http://www.coresecurity.com/content/winds3d-viewer-advisory","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Core Security Technologies","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/35764","name":"http://secunia.com/advisories/35764","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Winds3D Viewer Two Code Execution Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/35595","name":"http://www.securityfocus.com/bid/35595","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2009/1834","name":"http://www.vupen.com/english/advisories/2009/1834","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-2386","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-2386","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"2386","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"awingsoft","cpe5":"awakening_winds3d_viewer_plugin","cpe6":"3.0.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"2386","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"awingsoft","cpe5":"awakening_winds3d_viewer_plugin","cpe6":"3.5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:52:13.780Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35764","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/35764"},{"name":"35595","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/35595"},{"name":"ADV-2009-1834","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1834"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.coresecurity.com/content/winds3d-viewer-advisory"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-07-10T15:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"35764","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/35764"},{"name":"35595","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/35595"},{"name":"ADV-2009-1834","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1834"},{"tags":["x_refsource_MISC"],"url":"http://www.coresecurity.com/content/winds3d-viewer-advisory"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-2386","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35764","refsource":"SECUNIA","url":"http://secunia.com/advisories/35764"},{"name":"35595","refsource":"BID","url":"http://www.securityfocus.com/bid/35595"},{"name":"ADV-2009-1834","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1834"},{"name":"http://www.coresecurity.com/content/winds3d-viewer-advisory","refsource":"MISC","url":"http://www.coresecurity.com/content/winds3d-viewer-advisory"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-2386","datePublished":"2009-07-10T15:00:00.000Z","dateReserved":"2009-07-08T00:00:00.000Z","dateUpdated":"2024-09-16T19:24:28.990Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-07-10 15:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:awingsoft:awakening_winds3d_viewer_plugin:3.0.0.5:*:*:*:*:*:*:*","matchCriteriaId":"8E9ADF12-4B92-44B6-BD4A-F7766257549E"},{"vulnerable":true,"criteria":"cpe:2.3:a:awingsoft:awakening_winds3d_viewer_plugin:3.5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"6825AF8E-3F4E-4724-8B7D-E7FBCF72B53E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"2386","Ordinal":"1","Title":"CVE-2009-2386","CVE":"CVE-2009-2386","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"2386","Ordinal":"1","NoteData":"Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.","Type":"Description","Title":"CVE-2009-2386"},{"CveYear":"2009","CveId":"2386","Ordinal":"2","NoteData":"2009-07-10","Type":"Other","Title":"Published"}]}}}