vendor:
Java
by:
Michael Schierl, juan vazquez, Edward D. Teach, sinn3r
N/A
CVSS
N/A
Remote Code Execution
94
CWE
Product Name: Java
Affected Version From: 6 Update 27
Affected Version To: 7
Patch Exists: YES
Related CWE: CVE-2011-3544
CPE: a:oracle:java
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1455/, https://www.rapid7.com/db/vulnerabilities/apple-java-cve-2011-3544/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-3544/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1384/, https://www.rapid7.com/db/vulnerabilities/jre-vuln-cve-2011-3544/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-1380/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-3544/, https://www.rapid7.com/db/vulnerabilities/vmsa-2012-0003-cve-2011-3544/, https://www.rapid7.com/db/vulnerabilities/vmsa-2012-0005-cve-2011-3544/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2012-0034/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2011-3544/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-3544/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2011
Java Applet Rhino Script Engine Remote Code Execution
This module exploits a vulnerability in the Rhino Script Engine that can be used by a Java Applet to run arbitrary Java code outside of the sandbox. The vulnerability affects version 7 and version 6 update 27 and earlier, and should work on any browser that supports Java (for example: IE, Firefox, Google Chrome, etc)
Mitigation:
Update to the latest version of Java