service.real.comConfirmation
http://service.real.com/realplayer/security/10152010_player/en CVE-2010-3749
Real Networks RealPlayer SP - 'RecordClip' Method Remote Code Execution
Record summary
CVE-2010-3749 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a " (double quote) in an argument to the RecordClip method, aka "parameter injection."
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBReal Networks RealPlayer SP - 'RecordClip' Method Remote Code ExecutionExploitDB exploitby Sean de ReggeNot analyzed1 file
References
615991exploit
http://www.exploit-db.com/exploits/15991 44144vdb entry
http://www.securityfocus.com/bid/44144 44443vdb entry
http://www.securityfocus.com/bid/44443 zerodayinitiative.com
http://www.zerodayinitiative.com/advisories/ZDI-10-211 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-3749