Unrated severityNVD Advisory· Published Sep 18, 2008· Updated Apr 23, 2026
CVE-2008-1093
CVE-2008-1093
Description
Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.
Affected products
2- cpe:2.3:a:acresso:flexnet_connect:*:*:*:*:*:*:*:*
- cpe:2.3:a:acresso:intallshield_update_agent:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.kb.cert.org/vuls/id/837092nvdUS Government Resource
- secunia.com/advisories/31896nvd
- securityreason.com/securityalert/4268nvd
- www.securityfocus.com/archive/1/496389/100/0/threadednvd
- www.securityfocus.com/bid/31204nvd
- www.securitytracker.com/idnvd
- www.simplicity.net/vuln/CVE-2008-1093.txtnvd
- www.vupen.com/english/advisories/2008/2613nvd
News mentions
0No linked articles in our index yet.