CVE-2008-1116
Estado: ModificadaAlta (9.3)—💥 Exploit
Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 10%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Rising AntiVirus Online Scanner - Insecure Method Flaw (25/2/2008)
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/29109
- http://www.securityfocus.com/bid/27997
- http://www.vupen.com/english/advisories/2008/0683/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40838
- https://www.exploit-db.com/exploits/5188
- http://secunia.com/advisories/29109
- http://www.securityfocus.com/bid/27997
- http://www.vupen.com/english/advisories/2008/0683/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40838
- https://www.exploit-db.com/exploits/5188
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-1116",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-03-03T18:44:00.000",
"references": [
{
"url": "http://secunia.com/advisories/29109",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27997",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0683/references",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40838",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/5188",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29109",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27997",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0683/references",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40838",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/5188",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information."
},
{
"lang": "es",
"value": "Vulnarbilidad de métodos no seguros en el control ActiveX de Web Scan Object (OL2005.dll) en Rising Antivirus Online Scanner permite a atacantes remotos forzar la descarga y ejecución de código de su elección mediante el establecimiento de la propiedad BaseURL e invocando el método UpdateEngine.\r\nNOTA: algunos de estos detalles han sido obtenidos a partir de la información de terceros."
}
],
"lastModified": "2026-06-16T22:51:01.900",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rising_antivirus_international:rising_web_scan_object:18.0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B44E1BDE-E6E8-4805-8475-C39FC08F6B26"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}