CVE Database
/

CVE-2012-5003

Back to search

CVE-2012-5003

Published: Sep 19, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.

VendorProductVersions

n/a

n/a

affected
n/a

References

47685
third-party-advisory
x_refsource_SECUNIA
nxweb-applet-code-execution(72712)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now