CVE-2010-0589
published 2010-04-15CVE-2010-0589: The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs…
PriorityP344critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.76%
90.8th percentile
The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure_desktop | <= 3.5 | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop | — | — |
| cisco | secure_desktop_activex_control_code_execution | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Desktop ActiveX Control Code Execution Vulnerability
vendor_cisco
CVE-2010-0589 Cisco Secure Desktop ActiveX Control Code Execution Vulnerability
CVE-2010-0589: Cisco Secure Desktop ActiveX Control Code Execution Vulnerability
Cisco Secure Desktop contains a vulnerable ActiveX control that could allow an attacker to execute arbitrary code with the privileges of the user who is currently logged into the affected system. Cisco has released a free software update that addresses this vulnerability. There is a workaround that mitigates this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100414-csd .
Bug IDs: CSCta25876
GHSA
GHSA-2gxw-4wp7-72hf: A certain ActiveX control in CSDWebInstaller
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2011-0926 [CRITICAL] CWE-20 GHSA-2gxw-4wp7-72hf: A certain ActiveX control in CSDWebInstaller
A certain ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) does not properly verify the signature of an unspecified downloaded program, which allows remote attackers to execute arbitrary code by spoofing the CSD installation process, a different vulnerability than CVE-2010-0589.
GHSA
GHSA-4h59-jg65-9v45: The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller
ghsa_unreviewed·2022-05-14·CVSS 9.3
CVE-2011-0925 [CRITICAL] CWE-20 GHSA-4h59-jg65-9v45: The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller
The CSDWebInstallerCtrl ActiveX control in CSDWebInstaller.ocx in Cisco Secure Desktop (CSD) allows remote attackers to download an unintended Cisco program onto a client machine, and execute this program, by identifying a Cisco program with a Cisco digital signature and then renaming this program to inst.exe, a different vulnerability than CVE-2010-0589 and CVE-2011-0926.
GHSA
GHSA-rrfm-4fhv-2623: The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0589 [HIGH] CWE-20 GHSA-rrfm-4fhv-2623: The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3
The Web Install ActiveX control (CSDWebInstaller) in Cisco Secure Desktop (CSD) before 3.5.841 does not properly verify the signatures of downloaded programs, which allows remote attackers to force the download and execution of arbitrary files via a crafted web page, aka Bug ID CSCta25876.
Suricata
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0589 [HIGH] ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user SELECT
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user SELECT"; flow:established,to_server; http.uri; content:"/info_user.asp?"; nocase; content:"user="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0589; reference:url,www.milw0rm.com/exploits/3197; classtype:web-application-attack; sid:2005176; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techn
Suricata
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0589 [HIGH] ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user INSERT
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user INSERT"; flow:established,to_server; http.uri; content:"/info_user.asp?"; nocase; content:"user="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0589; reference:url,www.milw0rm.com/exploits/3197; classtype:web-application-attack; sid:2005148; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techn
Suricata
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0589 [HIGH] ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UPDATE
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UPDATE"; flow:established,to_server; http.uri; content:"/info_user.asp?"; nocase; content:"user="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-0589; reference:url,www.milw0rm.com/exploits/3197; classtype:web-application-attack; sid:2005151; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techni
Suricata
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0589 [HIGH] ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UNION SELECT
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user UNION SELECT"; flow:established,to_server; http.uri; content:"/info_user.asp?"; nocase; content:"user="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0589; reference:url,www.milw0rm.com/exploits/3197; classtype:web-application-attack; sid:2005147; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access
Suricata
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0589 [HIGH] ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user ASCII
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user ASCII"; flow:established,to_server; http.uri; content:"/info_user.asp?"; nocase; content:"user="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0589; reference:url,www.milw0rm.com/exploits/3197; classtype:web-application-attack; sid:2005150; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techn
Suricata
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0589 [HIGH] ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user DELETE
ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Forum Livre SQL Injection Attempt -- info_user.asp user DELETE"; flow:established,to_server; http.uri; content:"/info_user.asp?"; nocase; content:"user="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0589; reference:url,www.milw0rm.com/exploits/3197; classtype:web-application-attack; sid:2005149; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techn
No public exploits indexed.
No writeups or analysis indexed.
http://securitytracker.com/id?1023881http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtmlhttp://www.securityfocus.com/bid/39478http://www.zerodayinitiative.com/advisories/ZDI-10-072/https://exchange.xforce.ibmcloud.com/vulnerabilities/57812http://securitytracker.com/id?1023881http://www.cisco.com/en/US/products/products_security_advisory09186a0080b25d01.shtmlhttp://www.securityfocus.com/bid/39478http://www.zerodayinitiative.com/advisories/ZDI-10-072/https://exchange.xforce.ibmcloud.com/vulnerabilities/57812
2010-04-15
Published