Security Advisory

CVE-2008-1093

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-09-17 18:06:00
Last updated 2024-08-07 08:08:57
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.