Sploitus

CVE-2010-3749

2 known exploits for CVE-2010-3749

The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a " (double quote) in an argument to the RecordClip method, aka "parameter injection."

Affected products
Realplayer, Realplayer Sp
Realnetworks Realplayer
= 11.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, 11.0.5, 11.1
CVSS 2.0
9.3 HIGH
EPSS
25.6% (98th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2010-10-18
CVE-2010-3749 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2010-3749

Proof-of-concept code and exploit modules indexed by Sploitus