mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 15:15:46 +02:00
711 B
711 B
CVE-2012-1826
Description
dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.
POC
Reference
- http://dotcms.com/dotCMSVersions/
- http://dotcms.com/dotCMSVersions/
- http://www.kb.cert.org/vuls/id/898083
- http://www.kb.cert.org/vuls/id/898083
Github
No PoCs found on GitHub currently.