Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67cj-g286-m6rp

Опубликовано: 15 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.5
CVSS3: 8.8

Описание

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction.

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction.

EPSS

Процентиль: 44%
0.00216
Низкий

7.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction.

EPSS

Процентиль: 44%
0.00216
Низкий

7.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-319