Record summary

CVE-2010-3749 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.

Description

The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a " (double quote) in an argument to the RecordClip method, aka "parameter injection."

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBReal Networks RealPlayer SP - 'RecordClip' Method Remote Code ExecutionExploitDB exploitby Sean de ReggeNot analyzed1 file
ExploitDB

PoC details

References

6