ID | CVE-2012-1826 | ||||||
Sažetak | dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template. | ||||||
Reference | |||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:M/Au:S/C:P/I:P/A:P | ||||||
Zadnje važnije ažuriranje | 27-11-2012 - 04:41 | ||||||
Objavljeno | 08-06-2012 - 16:55 |