CVE-2009-2011
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 40.18% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- dxstudio/dx studio player
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35402Vendor Advisory
- http://www.coresecurity.com/content/DXStudio-player-firefox-pluginExploit
- http://www.dxstudio.com/forumtopic.aspx?topicid=b4152459-fb5f-4933-b700-b3fbd54f6bfdURL Repurposed
- http://www.securityfocus.com/archive/1/504195/100/0/threaded
- http://www.securityfocus.com/bid/35273Exploit, Patch
- http://www.vupen.com/english/advisories/2009/1561Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51035
- https://www.exploit-db.com/exploits/8922
- http://secunia.com/advisories/35402Vendor Advisory
- http://www.coresecurity.com/content/DXStudio-player-firefox-pluginExploit
- http://www.dxstudio.com/forumtopic.aspx?topicid=b4152459-fb5f-4933-b700-b3fbd54f6bfdURL Repurposed
- http://www.securityfocus.com/archive/1/504195/100/0/threaded
- http://www.securityfocus.com/bid/35273Exploit, Patch
- http://www.vupen.com/english/advisories/2009/1561Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51035
- https://www.exploit-db.com/exploits/8922
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.