The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-02-18 11:55
Updated : 2024-02-04 18:35
NVD link : CVE-2014-1861
Mitre link : CVE-2014-1861
CVE.ORG link : CVE-2014-1861
JSON object : View
Products Affected
jetroplatforms
- jetro_cockpit_secure_browsing
CWE
CWE-20
Improper Input Validation