Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mc8-6vfm-jpqx

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.

Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.

EPSS

Процентиль: 74%
0.00849
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 17 лет назад

Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.

EPSS

Процентиль: 74%
0.00849
Низкий

Дефекты

CWE-94