CVE-2009-0813
Imera TeamLinks Client - Remote Code Execution via ImeraIEPlugin ActiveX Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0813. PoCs published by Elazar.
AI-analyzed exploit summary This exploit leverages an insecure download and execution vulnerability in ImeraIEPlugin.dll (version 1.0.2.54) by manipulating the DownloadHost and DownloadURI parameters to fetch and execute arbitrary executables. The ActiveX control fails to validate the source, allowing remote code execution.
Description
Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters.
Exploits (1)
This exploit leverages an insecure download and execution vulnerability in ImeraIEPlugin.dll (version 1.0.2.54) by manipulating the DownloadHost and DownloadURI parameters to fetch and execute arbitrary executables. The ActiveX control fails to validate the source, allowing remote code execution.