PT-2009-3410 · Sopcast · Sopcast Sopcore Activex Control
Published
2009-03-04
·
Updated
2018-10-10
·
CVE-2009-0811
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SopCast SopCore ActiveX control version 3.0.3.501
Description
The issue is related to an insecure method in the SopCast SopCore ActiveX control, which allows remote attackers to execute arbitrary programs. This can be achieved by providing an executable file name as an argument to the
SetExternalPlayer method.Recommendations
For version 3.0.3.501, consider disabling the
SetExternalPlayer method until a patch is available to prevent remote attackers from executing arbitrary programs.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sopcast Sopcore Activex Control