← All CVEs

CVE-2009-1088

high · 9

Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime.

9
CVSS
12.0%
EPSS (exploit prob.)
96th
EPSS percentile
2009-03-25
Published

AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
hannonhillcascade5.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1088