PT-2009-3410 · Sopcast · Sopcast Sopcore Activex Control

Published

2009-03-04

·

Updated

2018-10-10

·

CVE-2009-0811

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SopCast SopCore ActiveX control version 3.0.3.501
Description The issue is related to an insecure method in the SopCast SopCore ActiveX control, which allows remote attackers to execute arbitrary programs. This can be achieved by providing an executable file name as an argument to the SetExternalPlayer method.
Recommendations For version 3.0.3.501, consider disabling the SetExternalPlayer method until a patch is available to prevent remote attackers from executing arbitrary programs.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0811

Affected Products

Sopcast Sopcore Activex Control