Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
No Machine NX Web Companion ‘nxapplet.jar’授权问题
Vulnerability Description
No Machine NX Web Companion 3.x和较早版本中的nxapplet.jar中存在漏洞,该漏洞源于未正确验证更新的真实性。用户协助的攻击者可利用该漏洞通过指向Trojan Horse client.zip更新文件中特制的(1)SiteUrl或(2)RedirectUrl参数执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A