The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2014-02/0075.html - | |
References | () http://blog.quaji.com/2014/02/remote-code-execution-on-all-enterprise.html - |
Information
Published : 2014-02-18 11:55
Updated : 2025-04-11 00:51
NVD link : CVE-2014-1861
Mitre link : CVE-2014-1861
CVE.ORG link : CVE-2014-1861
JSON object : View
Products Affected
jetroplatforms
- jetro_cockpit_secure_browsing
CWE
CWE-20
Improper Input Validation