exploit the possibilities
Showing 1 - 1 of 1 RSS Feed

Files

Sun Java Web Start Plugin Command Line Argument Injection
Posted Apr 15, 2010
Authored by jduck | Site metasploit.com

This Metasploit module exploits a flaw in the Web Start plugin component of Sun Java Web Start. The arguments passed to Java Web Start are not properly validated. By passing the lesser known -J option, an attacker can pass arbitrary options directly to the Java runtime. By utilizing the -XXaltjvm option, as discussed by Ruben Santamarta, an attacker can execute arbitrary code in the context of an unsuspecting browser user. This vulnerability was originally discovered independently by both Ruben Santamarta and Tavis Ormandy. Tavis reported that all versions since version 6 Update 10 "are believed to be affected by this vulnerability."

tags | exploit, java, web, arbitrary
MD5 | 7978de42024180d3eb9ce925a9229e45
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
BitMart Crypto Exchange Loses $150 Million To Hackers
Posted Dec 6, 2021

tags | headline, hacker, bank, cybercrime, data loss, cryptography
SolarWinds Hackers Keep Compromising Targets
Posted Dec 6, 2021

tags | headline, hacker, government, russia, cyberwar, backdoor
FBI: Cuban Ransomware Hits 49 Critical Infrastructure Organizations
Posted Dec 6, 2021

tags | headline, government, malware, usa, cyberwar, cuba, fbi, cryptography
American Diplomat's iPhones Compromised By NSO Group
Posted Dec 6, 2021

tags | headline, government, malware, usa, phone, flaw, cyberwar, israel, spyware, apple
US Rejects Calls For Regulating Or Banning Killer Robots
Posted Dec 3, 2021

tags | headline, government, usa, botnet, cyberwar, science, military
Researcher Found Way To Brute Force Verizon Customer PINs
Posted Dec 3, 2021

tags | headline, hacker, phone, password
Hackers Steal $119 Million From Web3 Crypto Project With Old School Attack
Posted Dec 3, 2021

tags | headline, hacker, bank, cybercrime, data loss, fraud, flaw, cryptography
Ransomware Attack On Planned Parenthood Steals Data Of 400k Patients
Posted Dec 3, 2021

tags | headline, privacy, malware, data loss, cryptography
Stealthy WIRTE Gang Targets Middle Eastern Governments
Posted Dec 2, 2021

tags | headline, hacker, government, malware, cyberwar, spyware
Facebook To Mandate High Security Program For Politicians, Journalists
Posted Dec 2, 2021

tags | headline, government, privacy, cyberwar, facebook, social
View More News →
packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close