« Volver al listado

CVE-2009-1064

Estado: ModificadaMedia (5.8)—

Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-1064",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-03-26T05:51:52.453",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/34200",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.waraxe.us/advisory-73.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49353",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/8257",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34200",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.waraxe.us/advisory-73.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49353",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/8257",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de inyección de argumento en orbitmxt.dll v2.1.0.2 del ActiveX Orbit Downloader  v2.8.7 y versiones previas, permite a atacantes remotos sobreescribir ficheros de su elección a través un espacio en blanco e interruptores de la línea de comandos seguidos de un nombre de ruta completo en el tercer argumento del método \"download\"."
    }
  ],
  "lastModified": "2026-06-16T23:06:25.613",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:orbit_downloader:orbit_downloader:2.6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D6523B1-6B03-43B6-AEFD-72B92019D992"
            },
            {
              "criteria": "cpe:2.3:a:orbit_downloader:orbit_downloader:2.6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7553CFDF-7CA8-4DAF-8FFF-3D9222C25937"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8309D23-4FB8-4D01-A152-14BF18C6D220",
              "versionEndIncluding": "2.8.7"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9582704-5578-48A0-A410-0F66F0BB85A9"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.6.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CEEC8A4-B3A3-447A-BFAD-0C663AF87E50"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.6.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDEDDF18-2B7F-4C36-AF04-FD8980A2F88A"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.6.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04A8333D-8F29-4DB7-95F4-948A4810D3B2"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3F23407-9615-4C6F-93C1-66BF0D2701B2"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.7.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC08EF4B-F0C0-4481-A939-F54B47144FD6"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.7.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B9B3EA76-C40F-4AE3-AA7E-C3001FDF2612"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.7.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6113A9CE-B5E9-4A0C-AD89-BD3B12BA4C04"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.7.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A9964A5-B840-43A0-9C47-7C4ED9DCB267"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.7.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B83AB34-50FE-4437-896D-4C33557FF4D7"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.7.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1C26D59-B436-4ED2-B13D-F81D3DE6D9C2"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90842889-9B97-492B-8F4A-020A9302D8A4"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95DD46C6-9D07-4A0E-801C-2EBFDB02E418"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A412B9B8-3011-4683-AD6B-1FC33E7C151C"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F3471391-3784-420B-A5D2-4D1BE9AFC0E7"
            },
            {
              "criteria": "cpe:2.3:a:orbitdownloader:orbit_downloader:2.8.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BD7B7CF-628E-4D9D-AF21-70E56F532F7E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}