PT-2018-14984 · Httl · Httl

Xqc2000

·

Publicado

2018-11-26

·

Atualizado

2018-12-19

·

CVE-2018-19531

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HTTL versions through 1.0.11
Description The issue allows remote command execution due to the unsafe use of java.beans.XMLEncoder by the decodeXml function when configured without an xml.codec setting.
Recommendations For versions through 1.0.11, consider configuring the xml.codec setting to prevent the unsafe use of java.beans.XMLEncoder until a patch is available.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19531

Produtos afetados

Httl