Security Advisory
CVE-2012-4009
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The WebView class in the Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that places this code into a local file associated with a file: URL.