Vulnerability Description
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Panda | Panda Activescan | 2.0 |
Related Weaknesses (CWE)
References
- http://karol.wiesek.pl/files/panda.tgzExploit
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063061.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063068.html
- http://secunia.com/advisories/30841Vendor Advisory
- http://www.securityfocus.com/bid/30086
- http://www.securitytracker.com/id?1020432
- http://www.vupen.com/english/advisories/2008/2008/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43587
- https://www.exploit-db.com/exploits/6004
- http://karol.wiesek.pl/files/panda.tgzExploit
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063061.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-July/063068.html
- http://secunia.com/advisories/30841Vendor Advisory
- http://www.securityfocus.com/bid/30086
- http://www.securitytracker.com/id?1020432
FAQ
What is CVE-2008-3156?
CVE-2008-3156 is a vulnerability with a CVSS score of 9.3 (HIGH). The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update...
How severe is CVE-2008-3156?
CVE-2008-3156 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3156?
Check the references section above for vendor advisories and patch information. Affected products include: Panda Panda Activescan.