what you don't know can hurt you
Showing 1 - 1 of 1 RSS Feed

Files

Sun Java Web Start Plugin Command Line Argument Injection
Posted Apr 19, 2010
Authored by jduck | Site metasploit.com

This Metasploit module exploits a flaw in the Web Start plugin component of Sun Java Web Start. The arguments passed to Java Web Start are not properly validated. By passing the lesser known -J option, an attacker can pass arbitrary options directly to the Java runtime. By utilizing the -XXaltjvm option, as discussed by Ruben Santamarta, an attacker can execute arbitrary code in the context of an unsuspecting browser user. This vulnerability was originally discovered independently by both Ruben Santamarta and Tavis Ormandy. Tavis reported that all versions since version 6 Update 10 "are believed to be affected by this vulnerability." In order for this module to work, it must be ran as root on a server that does not serve SMB. Additionally, the target host must have the WebClient service (WebDAV Mini-Redirector) enabled.

tags | exploit, java, web, arbitrary, root
advisories | CVE-2010-0886
MD5 | 497d4c86de502dbaa7ca516d3a23f53c
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Julian Assange's Extradition Hearing Set For 2020
Posted Jun 14, 2019

tags | headline, government, privacy, usa, britain, data loss, cyberwar, spyware
JavaScript Template Attacks Expose New Browser Fingerprinting Vectors
Posted Jun 14, 2019

tags | headline, flaw, spyware
High Severity Cisco Flaw In IOS XE Enables Device Takeover
Posted Jun 13, 2019

tags | headline, flaw, cisco
Facebook Emails Seem To Show Zuck Knew Of Privacy Issues
Posted Jun 13, 2019

tags | headline, privacy, email, data loss, facebook
Exim Email Servers Are Now Under Attack
Posted Jun 13, 2019

tags | headline, hacker, privacy, email, flaw
EFF Asks For DOJ Efforts To Break Facebook Encryption To Be Made Public
Posted Jun 13, 2019

tags | headline, government, privacy, usa, spyware, facebook, social, cryptography
Radiohead Sells Recordings To Public After Hacker Attempts Extortion
Posted Jun 12, 2019

tags | headline, hacker, cybercrime, data loss, fraud
Intel Fixes Severe NUC Firmware, Web Console Vulnerabilities
Posted Jun 12, 2019

tags | headline, flaw, patch, intel
Adobe Fixes Critical Security Flaws In Flash, ColdFusion, Campaign
Posted Jun 12, 2019

tags | headline, adobe, patch
Linux Command-Line Editors Vulnerable To High Severity Bug
Posted Jun 12, 2019

tags | headline, linux, flaw
View More News →
packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close