vendor:
The World Browser
by:
Ehsan Noreddini
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: The World Browser
Affected Version From: 3.0 Final
Affected Version To: 3.0 Final
Patch Exists: NO
Related CWE: CVE2014-6332
CPE:
Platforms Tested: Windows7
2015
The World Browser Remote Code Execution
The World Browser is a web browser that is vulnerable to remote code execution. An attacker can exploit this vulnerability by running a PHP code that creates a malicious file and opens it in the browser. This allows the attacker to execute arbitrary code on the victim's system.
Mitigation:
Update to the latest version of The World Browser.