← Back

CVE-2010-1911

nvd nist
Published: May 12, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance relies on a list of server domain names to restrict execution of ActiveX controls, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a DNS hijacking attack.

Affected (5)

3 products
Consona Dynamic Agent
Consona Live Assistance
Consona Subscriber Assistance
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Consona
All versions
All versions
All versions
All versions
All versions

Related CWEs

Timeline

No history available yet.