CVE Database
/

CVE-2008-4728

Back to search

CVE-2008-4728

Published: Oct 23, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method. NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.

VendorProductVersions

n/a

n/a

affected
n/a

References

6773
exploit
x_refsource_EXPLOIT-DB
6774
exploit
x_refsource_EXPLOIT-DB
31799
vdb-entry
x_refsource_BID
6776
exploit
x_refsource_EXPLOIT-DB
ADV-2008-2857
vdb-entry
x_refsource_VUPEN
32337
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now