vendor:
Boat Browser
by:
c0otlass
7,5
CVSS
HIGH
Remote code execution
94
CWE
Product Name: Boat Browser
Affected Version From: 8.0
Affected Version To: 8.0.1
Patch Exists: YES
Related CWE: 2014-4968
CPE: a:boat_browser:boat_browser
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Android 3.0 through 4.1.x
2014
Remote code execution vulnerability in Boat Browser
The WebView class and use of the WebView.addJavascriptInterface method has vulnerability which cause remote code in html page run in android device. A proof of concept is provided in the text.
Mitigation:
Update to the latest version of the browser