Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability
BID:35595
Info
Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability
| Bugtraq ID: | 35595 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2009 12:00AM |
| Updated: | Aug 31 2009 06:42PM |
| Credit: | Diego Juarez |
| Vulnerable: |
Awingsoft Winds3D Viewer 3.5.0.0 Awingsoft Winds3D Viewer 3.0.0.5 |
| Not Vulnerable: | |
Discussion
Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability
Winds3D Viewer is prone to a vulnerability that can allow malicious files to be downloaded an executed within the context of the affected browser that uses the plugin.
Successfully exploiting this issue will allow attackers to compromise the affected application that uses the plugin.
Winds3D Viewer 3.5.0.0 and 3.5.0.5 are vulnerable; other versions may also be affected.
Winds3D Viewer is prone to a vulnerability that can allow malicious files to be downloaded an executed within the context of the affected browser that uses the plugin.
Successfully exploiting this issue will allow attackers to compromise the affected application that uses the plugin.
Winds3D Viewer 3.5.0.0 and 3.5.0.5 are vulnerable; other versions may also be affected.
Exploit / POC
Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious webpage.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Winds3D Viewer 'GetURL()' Arbitrary File Download Vulnerability
References:
References:
- Awingsoft Awakening Winds3D Viewer remote command execution vulnerability (Core Security Technologies)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (Awingsoft)