JDownloader 'JDExternInterface.java' Remote Code Execution Vulnerability
BID:38143
Info
JDownloader 'JDExternInterface.java' Remote Code Execution Vulnerability
| Bugtraq ID: | 38143 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2010 12:00AM |
| Updated: | Feb 08 2010 12:00AM |
| Credit: | Matthias -apoc- Hecker |
| Vulnerable: |
JDownloader JDownloader 0 |
| Not Vulnerable: |
JDownloader JDownloader 0.9.334 |
Discussion
JDownloader 'JDExternInterface.java' Remote Code Execution Vulnerability
JDownloader is prone to a vulnerability that lets remote attackers execute arbitrary code.
Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process.
Versions prior to JDownloader 0.9.334 are vulnerable.
JDownloader is prone to a vulnerability that lets remote attackers execute arbitrary code.
Attackers can exploit this issue to execute arbitrary code within the context of the affected webserver process.
Versions prior to JDownloader 0.9.334 are vulnerable.
Exploit / POC
JDownloader 'JDExternInterface.java' Remote Code Execution Vulnerability
Attackers may exploit this issue through a browser.
The following proofs of concept are available:
Attackers may exploit this issue through a browser.
The following proofs of concept are available:
Solution / Fix
JDownloader 'JDExternInterface.java' Remote Code Execution Vulnerability
Solution:
Reports indicate that the vendor has fixed this issue. Please see the references for more information.
Solution:
Reports indicate that the vendor has fixed this issue. Please see the references for more information.
References
JDownloader 'JDExternInterface.java' Remote Code Execution Vulnerability
References:
References:
- Vendor Hompage (JDownloader)
- JDownloader Remote Code Execution (Matthias -apoc- Hecker
)