9.3

CVE-2008-2551

The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IconaInstant Messenger Version1.0.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 46.94% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/30512
Vendor Advisory
http://securityreason.com/securityalert/3926
http://www.securityfocus.com/archive/1/493019/100/0/threaded
http://www.securityfocus.com/bid/29519
http://www.vupen.com/english/advisories/2008/1733/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/42825
https://www.exploit-db.com/exploits/5732