PT-2009-1974 · Opensymphony · Opensymphony Xwork
Meder Kydyraliev
·
Published
2009-03-23
·
Updated
2022-05-17
·
CVE-2008-6504
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSymphony XWork versions 2.0.x through 2.0.5
OpenSymphony XWork versions 2.1.x through 2.1.1
Description
The issue allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects. This is due to the ParametersInterceptor in OpenSymphony XWork not properly restricting # (pound sign) references to context objects.
Recommendations
For OpenSymphony XWork versions 2.0.x through 2.0.5, update to version 2.0.6 or later.
For OpenSymphony XWork versions 2.1.x through 2.1.1, update to version 2.1.2 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensymphony Xwork