vendor:
Mac OS X
by:
Moritz Jodeit
7.5
CVSS
HIGH
Command Execution
78
CWE
Product Name: Mac OS X
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2007-5863
CPE: o:apple:mac_os_x
Platforms Tested: OSX
2007
Apple OS X Software Update Command Execution
This module exploits a feature in the Distribution Packages, which are used in the Apple Software Update mechanism. This feature allows for arbitrary command execution through JavaScript. This exploit provides the malicious update server. Requests must be redirected to this server by other means for this exploit to work.
Mitigation:
Unknown