CVE-2009-1064 | Date: (C)2009-03-26 (M)2023-12-22 |
Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method.
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V2 Severity: |
CVSS Score : 5.8 |
Exploit Score: 8.6 |
Impact Score: 4.9 |
|
CVSS V2 Metrics: |
Access Vector: NETWORK |
Access Complexity: MEDIUM |
Authentication: NONE |
Confidentiality: NONE |
Integrity: PARTIAL |
Availability: PARTIAL |
| |