Логотип exploitDog
bind:CVE-2018-14667
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-14667

Количество 3

Количество 3

redhat логотип

CVE-2018-14667

больше 7 лет назад

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2018-14667

больше 7 лет назад

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-j7mw-7crr-658v

больше 3 лет назад

Richfaces vulnerable to arbitrary code execution

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-14667

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVSS3: 9.8
89%
Высокий
больше 7 лет назад
nvd логотип
CVE-2018-14667

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

CVSS3: 9.8
89%
Высокий
больше 7 лет назад
github логотип
GHSA-j7mw-7crr-658v

Richfaces vulnerable to arbitrary code execution

CVSS3: 9.8
89%
Высокий
больше 3 лет назад

Уязвимостей на страницу