### [CVE-2009-2386](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2386) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method. ### POC #### Reference - http://www.coresecurity.com/content/winds3d-viewer-advisory #### Github No PoCs found on GitHub currently.