9.3
CVE-2010-1908
- EPSS 2.34%
- Veröffentlicht 12.05.2010 11:46:31
- Zuletzt bearbeitet 16.06.2026 23:19:34
- Erkennungen
The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict access to the HTTPDownloadFile, HTTPGetFile, Install, and RunCmd methods, which allows remote attackers to execute arbitrary programs via a URL in the url argument to (1) HTTPDownloadFile or (2) HTTPGetFile.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Consona ≫ Consona Dynamic Agent Version - Update - Edition enterprise
Consona ≫ Consona Dynamic Agent Version - Update - Edition marketing
Consona ≫ Consona Dynamic Agent Version - Update - Edition support
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.34% | 0.814 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
http://wintercore.com/en/component/content/article/7-media/18-wintercore-releases-an-advisory-for-consona-products.html
http://www.kb.cert.org/vuls/id/602801
http://www.securityfocus.com/archive/1/511176/100/0/threaded
http://www.wintercore.com/downloads/rootedcon_0day.pdf
http://secunia.com/advisories/39751