Title : HP-UX Java Runtime Environment (JRE) Applet Security Bypass Issue VUPEN ID : VUPEN/ADV-2005-1593 CVE ID : CVE-2005-1974 CWE ID : CWE-
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-08-31
Technical Description
A vulnerability was identified in HP-UX, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to an error in Java Runtime Environment (JRE) when handling specially crafted applets, which may be exploited via a malicious webpage to read and/write arbitrary files on a vulnerable system and execute local applications with the privileges of the user running the untrusted applet. For additional information, see : VUPEN/ADV-2005-0764