Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1885
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1885

Description:
Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attackers to download arbitrary code onto a client system via a .. (dot dot) in the SkinPath parameter and a .zip URL in the HttpSkin parameter. NOTE: this can be leveraged for code execution by writing to a Startup folder.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41743

SAID
  Secunia Advisory: SA29692

MILW0RM
  http://www.milw0rm.com/exploits/5397

BUGTRAQ
  http://seclists.org/bugtraq/2008/Apr/0065.html

BID
  28666


Return to the previous page.