Files
CVEs-PoC/2015/CVE-2015-1835.md
T
2024-06-18 02:51:15 +02:00

18 lines
814 B
Markdown

### [CVE-2015-1835](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1835)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
### POC
#### Reference
- http://blog.trendmicro.com/trendlabs-security-intelligence/trend-micro-discovers-apache-vulnerability-that-allows-one-click-modification-of-android-apps/
#### Github
No PoCs found on GitHub currently.