메뉴 건너뛰기

GREATUSER

cve

CVE-2017-9805

관리자 2017.09.16 14:00 조회 수 : 12

The REST Plugin in Apache Struts 2.1.2 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-9805
번호 제목 글쓴이 날짜 조회 수
362 CVE-2017-1693 관리자 2018.01.25 6
361 CVE-2018-5785 관리자 2018.01.25 6
360 CVE-2017-16615 관리자 2017.11.09 6
359 CVE-2017-16642 관리자 2017.11.09 6
358 CVE-2017-2866 관리자 2017.11.09 6
357 CVE-2017-2909 관리자 2017.11.09 6
356 CVE-2017-2912 관리자 2017.11.09 6
355 CVE-2017-2889 관리자 2017.11.09 6
354 CVE-2017-14025 관리자 2017.11.09 6
353 CVE-2017-7934 관리자 2017.08.27 6
352 CVE-2017-13648 (graphicsmagick) 관리자 2017.08.27 6
351 CVE-2017-5685 관리자 2017.04.04 6
350 CVE-2017-5686 관리자 2017.04.04 6
349 CVE-2017-7397 관리자 2017.04.04 6
348 CVE-2017-7407 관리자 2017.04.04 6
위로