CVE-2009-2386 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 5.1% (pctl 92)
Patch early
A public exploit exists.
Description
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 5.12% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-07-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| awingsoft | awakening winds3d viewer plugin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Winds3D Viewer 3 - 'GetURL()' Arbitrary File Download | 2009-06-08 |
References
- http://secunia.com/advisories/35764
- http://www.coresecurity.com/content/winds3d-viewer-advisory
- http://www.securityfocus.com/bid/35595
- http://www.vupen.com/english/advisories/2009/1834
- http://secunia.com/advisories/35764
- http://www.coresecurity.com/content/winds3d-viewer-advisory
- http://www.securityfocus.com/bid/35595
- http://www.vupen.com/english/advisories/2009/1834
→ the Explorer · watch your stack · NVD