Compaq SpawnApp Vulnerability
BID:557
Info
Compaq SpawnApp Vulnerability
| Bugtraq ID: | 557 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 28 1998 12:00AM |
| Updated: | Nov 28 1998 12:00AM |
| Credit: | Vulnerability discovered by Frank Farance <[email protected]> in November 1998. Additional information posted to NTBugtraq by Richard M. Smith <[email protected]> July 26 and 28, 1999. |
| Vulnerable: |
Compaq Java Applet for Presario |
| Not Vulnerable: | |
Discussion
Compaq SpawnApp Vulnerability
Some Compaq computers come with a Java applet called SpawnApp. This applet is used to run Compaq diagnostic utilities from the local hard drive when certain Compaq websites are viewed. The problem is that the applet can run any program, and can be used by any webpage. This applet is signed as secure by Compaq.
Some Compaq computers come with a Java applet called SpawnApp. This applet is used to run Compaq diagnostic utilities from the local hard drive when certain Compaq websites are viewed. The problem is that the applet can run any program, and can be used by any webpage. This applet is signed as secure by Compaq.
References
Compaq SpawnApp Vulnerability
References:
References:
- Ghosts in the Machine (Wired News)
- IE 4.0 Security Problem (Frank Farance)