Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via the (1) -J or (2) -XXaltjvm argument to javaws.exe, which is processed by the launch method. NOTE: some of these details are obtained from third party information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle Java NAAPI插件和Java Deployment Toolkit URI处理程序参数注入漏洞
Vulnerability Description
Java NAAPI插件和Java Deployment Toolkit的URI处理程序存在参数注入漏洞。当在Windows下运行时(Linux也有可能),远程攻击者可通过由javaws.exe启动方法处理的(1)-J或(2)-Xxaltjvm参数执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A