CVE-2013-1488

Oracle Jdk - Code Injection

Title source: rule

Description

The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to execute arbitrary code via unspecified vectors involving reflection, Libraries, "improper toString calls," and the JDBC driver manager, as demonstrated by James Forshaw during a Pwn2Own competition at CanSecWest 2013.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/26135
nomisec WORKING POC 5 stars
by v-p-b · poc
https://github.com/v-p-b/buherablog-cve-2013-1488
metasploit WORKING POC EXCELLENT
by James Forshaw, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/java_jre17_driver_manager.rb

References (22)

... and 2 more

Scores

EPSS 0.8625
EPSS Percentile 99.4%

Details

CWE
CWE-94
Status published
Products (2)
oracle/jdk 1.7.0 update17
oracle/jre 1.7.0 update17
Published Mar 08, 2013
Tracked Since Feb 18, 2026