CVE-2008-4385
high · 9.3Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the download and execution of arbitrary programs via by specifiying a malicious website argument to the Init method in (1) a certain ActiveX control (sysreqlab2.cab, sysreqlab.dll, sysreqlabsli.dll, or sysreqlab2.dll) and (2) a certain Java applet in RLApplet.class in sysreqlab2.jar or sysreqlab.jar.
9.3
CVSS
37.7%
EPSS (exploit prob.)
98th
EPSS percentile
2008-10-14
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| systemrequirementslab | system_requirements_lab | 3 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/32236
- http://www.kb.cert.org/vuls/id/166651
- http://www.sec-consult.com/files/20081016-0_sysreqlab.txt
- http://www.securityfocus.com/archive/1/497400
- http://www.securityfocus.com/bid/31752
- http://www.systemrequirementslab.com/bulletins/security_bulletin_1.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45873
- http://secunia.com/advisories/32236
- http://www.kb.cert.org/vuls/id/166651
- http://www.sec-consult.com/files/20081016-0_sysreqlab.txt
- http://www.securityfocus.com/archive/1/497400
- http://www.securityfocus.com/bid/31752
- http://www.systemrequirementslab.com/bulletins/security_bulletin_1.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45873
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-4385