The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-02-18 03:55
Updated : 2014-02-20 18:04
NVD link : CVE-2014-1861
Mitre link : CVE-2014-1861
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
jetroplatforms
- jetro_cockpit_secure_browsing