Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.
Advisories
Source ID Title
EUVD EUVD EUVD-2009-3557 Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T06:31:10.651Z

Reserved: 2009-10-07T00:00:00

Link: CVE-2009-3576

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-11-24T17:30:00.233

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-3576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.