HIGH · 9.3

CVE-2009-1792

The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary c...

Vulnerability Description

The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument (the sURL argument).

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
StonetripS3Dplayer Standalone1.6.2.4
StonetripS3Dplayer Web1.6.0.0
MicrosoftWindowsAll versions
AppleMacosAll versions
LinuxLinux KernelAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-1792?

CVE-2009-1792 is a vulnerability with a CVSS score of 9.3 (HIGH). The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary c...

How severe is CVE-2009-1792?

CVE-2009-1792 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-1792?

Check the references section above for vendor advisories and patch information. Affected products include: Stonetrip S3Dplayer Standalone, Stonetrip S3Dplayer Web, Microsoft Windows, Apple Macos, Linux Linux Kernel.