exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 1 - 1 of 1 RSS Feed

Files

Sun Java Web Start Plugin Command Line Argument Injection
Posted Apr 15, 2010
Authored by jduck | Site metasploit.com

This Metasploit module exploits a flaw in the Web Start plugin component of Sun Java Web Start. The arguments passed to Java Web Start are not properly validated. By passing the lesser known -J option, an attacker can pass arbitrary options directly to the Java runtime. By utilizing the -XXaltjvm option, as discussed by Ruben Santamarta, an attacker can execute arbitrary code in the context of an unsuspecting browser user. This vulnerability was originally discovered independently by both Ruben Santamarta and Tavis Ormandy. Tavis reported that all versions since version 6 Update 10 "are believed to be affected by this vulnerability."

tags | exploit, java, web, arbitrary
SHA-256 | 2e5503b022c0eff22f86ef53b4b82291d06f5226c0191d0bf171a4153b4e71ac
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
US Air Force Reveals The B-21 Raider Stealth Bomber
Posted Dec 3, 2022

tags | headline, government, usa, military
Rackspace Rocked By Security Incident
Posted Dec 3, 2022

tags | headline, hacker, email, denial of service
Darknet Markets Generate Millions In Revenue Selling Stolen Personal Data
Posted Dec 3, 2022

tags | headline, hacker, privacy, cybercrime, data loss, fraud
New Malware Is Nuking Data In Russian Courts
Posted Dec 3, 2022

tags | headline, government, malware, russia, data loss
After FTX Collapse, Pressure Builds For Tougher Crypto Rules
Posted Dec 2, 2022

tags | headline, government, bank, data loss, fraud, cryptography
Proton Calendar On iOS Encrypts More Of Your Work/Life Cloud Data
Posted Dec 2, 2022

tags | headline, privacy, cryptography
Mozilla, Microsoft Drop TrustCor As Root Certificate Authority
Posted Dec 2, 2022

tags | headline, microsoft, mozilla, firefox, cryptography
Nvidia Patches 29 GPU Driver Bugs That Could Lead To Code Execution, Device Takeover
Posted Dec 2, 2022

tags | headline, flaw, patch
Researchers Used A Sirius XM Bug To Easily Hijack A Bunch Of Different Cars
Posted Dec 1, 2022

tags | headline, hacker, flaw
Browser Zero Days Linked To Commercial IT Firm In Spain
Posted Dec 1, 2022

tags | headline, microsoft, google, mozilla, firefox, zero day, chrome
View More News →
packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close