Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GetAccess Remote Arbitrary Java Code Execution Vulnerability

GetAccess allows administration of individual user access rights and customer profiles on high-volume 'portal' websites.

A flaw exists in GetAccess' execution of java class files. When reading in filenames, input is not validated and directory traversals can be used to execute java class files anywhere on the filesystem.







 

Privacy Statement
Copyright 2009, SecurityFocus