CORE IMPACT v10.5 - Exploits Update (Mon Sep 06 2010)
Atlassian FishEye Struts 2 ParametersInterceptor Remote Code Execution Exploit
Exploits/Remote Code Execution [Windows]
Mon Sep 06 2010
The ParametersInterceptor class of XWork framework, part of the Struts 2 web framework, as shipped with Atlassian FishEye, does not properly restrict access to server-side objects. This can be exploited by remote unauthenticated attackers to modify server-side objects and e.g. execute arbitrary commands via specially crafted OGNL (Object-Graph Navigation Language) expressions.
Exploits Vulnerabiltiy: CVE-2010-1870











