Winds3D Viewer 3 - 'GetURL()' Arbitrary File Download



EKU-ID: 37943 CVE: CVE-2009-2386;OSVDB-55863 OSVDB-ID:
Author: Diego Juarez Published: 2009-06-08 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/35595/info

Winds3D Viewer is prone to a vulnerability that can allow malicious files to be downloaded an executed within the context of the affected browser that uses the plugin.

Successfully exploiting this issue will allow attackers to compromise the affected application that uses the plugin.

Winds3D Viewer 3.5.0.0 and 3.5.0.5 are vulnerable; other versions may also be affected.

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/33067.usr