CVE-2010-0189

A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.
References
Link Resource
http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx
http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html
http://blogs.zdnet.com/security/?p=5505
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856
http://secunia.com/advisories/38729 Vendor Advisory
http://securitytracker.com/id?1023651
http://www.adobe.com/support/security/bulletins/apsb10-08.html Patch Vendor Advisory
http://www.akitasecurity.nl/advisory.php?id=AK20090401
http://www.osvdb.org/62547
http://www.securityfocus.com/bid/38313
http://www.vupen.com/english/advisories/2010/0459 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/56370
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7182
http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx
http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html
http://blogs.zdnet.com/security/?p=5505
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856
http://secunia.com/advisories/38729 Vendor Advisory
http://securitytracker.com/id?1023651
http://www.adobe.com/support/security/bulletins/apsb10-08.html Patch Vendor Advisory
http://www.akitasecurity.nl/advisory.php?id=AK20090401
http://www.osvdb.org/62547
http://www.securityfocus.com/bid/38313
http://www.vupen.com/english/advisories/2010/0459 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/56370
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7182
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nos_microsystems:getplus_download_manager:1.5.2.35:*:*:*:*:*:*:*
cpe:2.3:a:adobe:download_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:11

Type Values Removed Values Added
References () http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx - () http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspx -
References () http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html - () http://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.html -
References () http://blogs.zdnet.com/security/?p=5505 - () http://blogs.zdnet.com/security/?p=5505 -
References () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856 - () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856 -
References () http://secunia.com/advisories/38729 - Vendor Advisory () http://secunia.com/advisories/38729 - Vendor Advisory
References () http://securitytracker.com/id?1023651 - () http://securitytracker.com/id?1023651 -
References () http://www.adobe.com/support/security/bulletins/apsb10-08.html - Patch, Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb10-08.html - Patch, Vendor Advisory
References () http://www.akitasecurity.nl/advisory.php?id=AK20090401 - () http://www.akitasecurity.nl/advisory.php?id=AK20090401 -
References () http://www.osvdb.org/62547 - () http://www.osvdb.org/62547 -
References () http://www.securityfocus.com/bid/38313 - () http://www.securityfocus.com/bid/38313 -
References () http://www.vupen.com/english/advisories/2010/0459 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/0459 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/56370 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/56370 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7182 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7182 -

Information

Published : 2010-02-23 20:30

Updated : 2024-11-21 01:11


NVD link : CVE-2010-0189

Mitre link : CVE-2010-0189

CVE.ORG link : CVE-2010-0189


JSON object : View

Products Affected

adobe

  • download_manager

nos_microsystems

  • getplus_download_manager
CWE
CWE-20

Improper Input Validation