The Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN23568423/index.html | third party advisory |
http://jvndb.jvn.jp/jvndb/JVNDB-2012-000083 | third party advisory |
http://cs.cybozu.co.jp/information/20120910up01.php | vendor advisory |