Files
CVEs-PoC/2019/CVE-2019-10182.md
T
2024-06-18 02:51:15 +02:00

1.1 KiB

CVE-2019-10182

Description

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

POC

Reference

Github