{ "schema_version": "1.4.0", "id": "GHSA-9qpj-2qwq-5f72", "modified": "2022-05-17T04:52:37Z", "published": "2022-05-17T04:52:37Z", "aliases": [ "CVE-2014-1861" ], "details": "The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-1861" }, { "type": "WEB", "url": "http://archives.neohapsis.com/archives/bugtraq/2014-02/0075.html" }, { "type": "WEB", "url": "http://blog.quaji.com/2014/02/remote-code-execution-on-all-enterprise.html" } ], "database_specific": { "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2014-02-18T11:55:00Z" } }