knowledge is security
Showing 1 - 1 of 1 RSS Feed

Files

Zero Day Initiative Advisory 08-042
Posted Jul 17, 2008
Authored by Tipping Point, Peter Csepely | Site zerodayinitiative.com

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Sun Java Web Start. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. The specific flaw exists in the writeManifest() method of the CacheEntry class. A directory traversal flaw in this method allows the creation of arbitrary files on the target system. After the file has been created, a call to Runtime.getRuntime.exec() can be used to execute the file.

tags | advisory, java, remote, web, arbitrary
MD5 | 40bc93865482ae2445c34853dcd2207d
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close