Remote Code Execution Vulnerability in Sun Java Virtual Machine
CVE-2007-5375
Currently unrated
What is CVE-2007-5375?
A vulnerability exists in the Sun Java Virtual Machine due to an interpretation conflict that allows user-assisted remote attackers to exploit a DNS rebinding attack. This can occur when an intranet web server serves an HTML document referencing a Java applet with the 'mayscript=true' parameter through a local relative URI. This misconfiguration can lead to the execution of arbitrary JavaScript in the context of the intranet, potentially compromising sensitive data and application integrity.
References
Timeline
Vulnerability published
Vulnerability Reserved