← Back

CVE-2010-1913

nvd nist
Published: May 12, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The default configuration of pluginlicense.ini for the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance, when downloaded from a server operated by Telefonica or possibly other companies, contains an incorrect DNS whitelist that includes the DNS hostnames of home computers of many persons, which allows remote attackers to bypass intended restrictions on ActiveX execution by hosting an ActiveX control on an applicable home web server.

Affected (5)

3 products
Consona Dynamic Agent
Consona Live Assistance
Consona Subscriber Assistance
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Consona
All versions
All versions
All versions
All versions
All versions

Related CWEs

Timeline

No history available yet.