Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Microsoft Java Virtual Machine CODEBASE Parameter File Disclosure Vulnerability

A vulnerability has been found in the Microsoft JVM that may allow an attacker to misrepresent the location of a malicious Java applet. Through the use of an APPLET HTML tag, an attacker can specify a false value for the 'CODEBASE' parameter. An attacker can exploit this vulnerability to load a malicious applet from a remote site and trick the Virtual Machine into thinking that it was executed from a trusted location, such as the vulnerable system's hard drive. This will allow an attacker to obtain access to potentially sensitive files on a vulnerable system or network shares the user has access to.

This vulnerability was originally described in BID 6365. It is now being assigned its own BugTraq ID.







 

Privacy Statement
Copyright 2008, SecurityFocus