CVE-2012-4011: OS Command Injection
Published Sep 8, 2012
·Updated
The Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
Affected Software
1 affected component
Cybozu Kunai Android<=2.0.5
Event History
Sep 8, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4011?
CVE-2012-4011 is rated as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2012-4011?
To fix CVE-2012-4011, update the Cybozu KUNAI application to version 2.0.6 or later.
3
What types of attacks are possible due to CVE-2012-4011?
Due to CVE-2012-4011, attackers can execute arbitrary Java methods and access sensitive information remotely.
4
Which versions of Cybozu KUNAI are affected by CVE-2012-4011?
CVE-2012-4011 affects all versions of Cybozu KUNAI prior to 2.0.6.
5
Is CVE-2012-4011 a mobile application vulnerability?
Yes, CVE-2012-4011 specifically affects the Android version of the Cybozu KUNAI mobile application.