peter bassill · operator
$ cve CVE-2008-1116 JSON

CVE-2008-1116 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 10.2% (pctl 96)

Patch early

A public exploit exists.

Description

Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS10.17% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2008-03-03
Last modified2026-06-16

Affected (1)

VendorProduct
rising antivirus internationalrising web scan object

Public exploits

SourceTitleDate
exploit-dbRising AntiVirus Online Scanner - Insecure Method Flaw2008-02-25

References

→ the Explorer  ·  watch your stack  ·  NVD