The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://magazine.cybozulive.com/2012/08/291200.html | |
http://jvndb.jvn.jp/jvndb/JVNDB-2012-000081 | third party advisory |
http://jvn.jp/en/jp/JVN23009798/index.html | third party advisory |