9.3

CVE-2008-4728

Exploit
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method.  NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HummingbirdDeployment Wizard Version2008
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 31.63% 0.981
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/32337
Vendor Advisory
http://www.securityfocus.com/bid/31799
http://www.shinnai.net/xplits/TXT_2XfQ1sHruhjaoePszNTG.html
Exploit
URL Repurposed
http://www.shinnai.net/xplits/TXT_JqLchaIAfq4kSH0NsvJO.html
Exploit
URL Repurposed
http://www.shinnai.net/xplits/TXT_L0z0Mimixdsko8kI6VFW.html
Exploit
URL Repurposed
http://www.vupen.com/english/advisories/2008/2857
https://exchange.xforce.ibmcloud.com/vulnerabilities/45961
https://www.exploit-db.com/exploits/6773
https://www.exploit-db.com/exploits/6774
https://www.exploit-db.com/exploits/6776