Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-3433 (download_accelerator_plus)

BugsAlert Home > CVE-2008-3433 (download_accelerator_plus)
 
 

SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3433

Learn more about CVE-2008-3433 (download_accelerator_plus)
 
Tags: cve-2008-3433 download accelerator

Related Items

      WORM_LEGMIR.DN

      IBM Tivoli Business Service Manager Password Disclosure Vulnerabilities

      Death of the Internet Foretold

      CVE-2008-4046 (elitecms)

      PE_VIRUT.XO-4

      Foresight: rsync

      WebGUI Security Bypass and Cross-Site Scripting

 

Pixel