VDB
CVE-2008-1093
CVE-2008-1093
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.
EPSS 0.75% · 73.5th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
0.75%
73.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| acresso | flexnet_connect | |
| n/a | n/a | n/a |
| acresso | intallshield_update_agent |
Timeline
- Sep 17, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://www.simplicity.net/vuln/CVE-2008-1093.txt url
- ADV-2008-2613 vdb
- 31896 third-party-advisory
- 31204 vdb
- 20080916 InstallShield Update Agent - Downloads and executes "Rule Scripts" insecurely. mailing-list
- 4268 third-party-advisory
- VU#837092 third-party-advisory
- 1020893 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2008-1093 advisory