JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
References
Configurations
History
No history.
Information
Published : 2015-03-26 14:59
Updated : 2025-04-12 10:46
NVD link : CVE-2015-0279
Mitre link : CVE-2015-0279
CVE.ORG link : CVE-2015-0279
JSON object : View
Products Affected
redhat
- richfaces
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')