Vulnerabilities > CVE-2008-4728 - Unspecified vulnerability in Hummingbird Deployment Wizard 2008

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
hummingbird
exploit available

Summary

Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method. NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.

Vulnerable Configurations

Part Description Count
Application
Hummingbird
1

Exploit-Db

  • descriptionHummingbird Deployment Wizard 2008 ActiveX File Execution(2). CVE-2008-4728. Remote exploit for windows platform
    fileexploits/windows/remote/6776.html
    idEDB-ID:6776
    last seen2016-02-01
    modified2008-10-17
    platformwindows
    port
    published2008-10-17
    reportershinnai
    sourcehttps://www.exploit-db.com/download/6776/
    titleHummingbird Deployment Wizard 2008 - ActiveX File Execution2
    typeremote
  • descriptionHummingbird Deployment Wizard 2008 ActiveX Command Execution. CVE-2008-4728. Remote exploit for windows platform
    fileexploits/windows/remote/6773.html
    idEDB-ID:6773
    last seen2016-02-01
    modified2008-10-17
    platformwindows
    port
    published2008-10-17
    reportershinnai
    sourcehttps://www.exploit-db.com/download/6773/
    titleHummingbird Deployment Wizard 2008 - ActiveX Command Execution
    typeremote
  • descriptionHummingbird Deployment Wizard 2008 Registry Values Creation/Change. CVE-2008-4728. Remote exploit for windows platform
    fileexploits/windows/remote/6774.html
    idEDB-ID:6774
    last seen2016-02-01
    modified2008-10-17
    platformwindows
    port
    published2008-10-17
    reportershinnai
    sourcehttps://www.exploit-db.com/download/6774/
    titleHummingbird Deployment Wizard 2008 Registry Values Creation/Change
    typeremote