Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10.5 - Exploits Update (Mon Sep 06 2010)

Atlassian FishEye Struts 2 ParametersInterceptor Remote Code Execution Exploit

Exploits/Remote Code Execution  [Windows]




• Mon Sep 06 2010
The ParametersInterceptor class of XWork framework, part of the Struts 2 web framework, as shipped with Atlassian FishEye, does not properly restrict access to server-side objects. This can be exploited by remote unauthenticated attackers to modify server-side objects and e.g. execute arbitrary commands via specially crafted OGNL (Object-Graph Navigation Language) expressions.

Exploits Vulnerabiltiy: CVE-2010-1870



< Back to Product Updates