### CVE-2017-7821
"browser.downloads addon feature may be used for RCE"
Steps:
1. Go to 'about:debugging'
2. Unpack attached PoC somewhere
3. Back in 'about:debugging' choose 'Load temp addon' and choose the poc
4. jar file is automatically downloaded and executed.
We are able to download and execute jar files automatically.
暂无评论