.:[ packet storm ]:.
                           
it's okay to have the details
it's okay to have the details

 ///  File Name:ZDI-08-042.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the writeManifest() method of the CacheEntry class. A directory traversal flaw in this method allows the creation of arbitrary files on the target system. After the file has been created, a call to Runtime.getRuntime.exec() can be used to execute the file.
Author:Peter Csepely
Homepage:http://www.zerodayinitiative.com/
File Size:3411
Last Modified:Jul 17 16:11:03 2008
MD5 Checksum:40bc93865482ae2445c34853dcd2207d

 .:. Back