CVE-2009-4850
Awingsoft Awakening Winds3D Viewer Plugin 3.5.0.9 - Remote Code Execution via SceneURL Property
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-4850.
PoCs published by Metasploit, jduck, including Metasploit module exploits/windows/browser/awingsoft_winds3d_sceneurl.
AI-analyzed exploit summary This Metasploit module exploits an untrusted program execution vulnerability in AwingSoft Winds3D Player 3.5 by setting the 'SceneURL' parameter to a malicious executable URL, leading to arbitrary code execution.
Description
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value with a URL for a .exe file.
Exploits (2)
This Metasploit module exploits an untrusted program execution vulnerability in AwingSoft Winds3D Player 3.5 by setting the 'SceneURL' parameter to a malicious executable URL, leading to arbitrary code execution.
This Metasploit module exploits an untrusted program execution vulnerability in AwingSoft Winds3D Player 3.5 by setting the 'SceneURL' parameter to a malicious executable URL, leading to arbitrary code execution.