PT-2009-4465 · Mozilla+1 · Firefox+1

·

CVE-2009-2011

·

Published

2009-06-16

·

Updated

2024-02-14

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Worldweaver DX Studio Player versions prior to 3.0.29.1
Description: The issue allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes the shell.execute JavaScript API method, due to a lack of access restriction to this method when the player is used as a plug-in for Firefox.
Recommendations: For versions prior to 3.0.29.1, consider disabling the shell.execute JavaScript API method as a temporary workaround until a patch is available. Restrict access to .dxstudio files that may invoke this method to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2011

Affected Products

Firefox
Worldweaver Dx Studio Player