20080407 CDNetworks Nefficient Download(NeffyLauncher.dll) Vulnerabilitiesmailing list
http://seclists.org/bugtraq/2008/Apr/0065.html CVE-2008-1886
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
Record summary
CVE-2008-1886 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauthorized use of the control, which allows remote attackers to bypass this protection mechanism by calculating the required KeyCode. NOTE: this can be used by arbitrary web sites to host exploit code that targets this control.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCDNetworks Nefficient Download - 'NeffyLauncher.dll' Code ExecutionExploitDB exploitby Simon RyeoNot analyzed1 file
References
528666vdb entry
http://www.securityfocus.com/bid/28666 nefficientdownload-keycode-security-bypass(41933)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41933 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1886 5397exploit
https://www.exploit-db.com/exploits/5397