Vulnerabilities > Acresso > Intallshield Update Agent

DATE CVE VULNERABILITY TITLE RISK
2008-09-18 CVE-2008-1093 Code Injection vulnerability in Acresso Flexnet Connect and Intallshield Update Agent
Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.
network
acresso CWE-94
critical
9.3