DXStudio.Firefox.Plugin.Command

NameDXStudio.Firefox.Plugin.Command.Execution
Release DateSep 24, 2009
SeverityHigh
ImpactSystem compromise
DescriptionThis indicates an attack attempt against a command execution vulnerability in DXStudio Firefox Plugin.

The vulnerability is caused by an error when the vulnerable software handles a malicious shell.execute script. It allows a remote attacker to execute arbitrary command via sending a crafted web page.
Affected ProductsWorldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1
Recommended ActionsUpgrade to DX Studio Player version v3.0.29.1 or later.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2011
Reference: VID-17707