CVE-2010-0189: Input Validation
A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0189?
CVE-2010-0189 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2010-0189?
To fix CVE-2010-0189, users should upgrade to the latest version of NOS Microsystems getPlus Download Manager or Adobe Download Manager.
What types of attacks does CVE-2010-0189 enable?
CVE-2010-0189 enables remote attackers to force the download and installation of arbitrary software on a user's system.
Which versions are affected by CVE-2010-0189?
CVE-2010-0189 affects NOS Microsystems getPlus Download Manager version 1.5.2.35 and all versions of Adobe Download Manager up to 1.6.2.60.
Is CVE-2010-0189 exploitable over the internet?
Yes, CVE-2010-0189 is exploitable over the internet, making it a significant security risk for users.