CVE-2008-1885
Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attackers to download arbitrary code onto a client system via a ..
Does this matter?
Lower severity and a low EPSS score (4.07%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download allows remote attackers to download arbitrary code onto a client system via a .. (dot dot) in the SkinPath parameter and a .zip URL in the HttpSkin parameter. NOTE: this can be leveraged for code execution by writing to a Startup folder.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.07% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cdnetworks/download client
- Source
- cve@mitre.org
References
- http://seclists.org/bugtraq/2008/Apr/0065.html
- http://secunia.com/advisories/29692Vendor Advisory
- http://www.securityfocus.com/bid/28666
- http://www.vupen.com/english/advisories/2008/1186
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41743
- https://www.exploit-db.com/exploits/5397
- http://seclists.org/bugtraq/2008/Apr/0065.html
- http://secunia.com/advisories/29692Vendor Advisory
- http://www.securityfocus.com/bid/28666
- http://www.vupen.com/english/advisories/2008/1186
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41743
- https://www.exploit-db.com/exploits/5397
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.