CVE-2013-4212
medium · 6.8Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka "OGNL Injection."
6.8
CVSS
81.1%
EPSS (exploit prob.)
100th
EPSS percentile
2013-12-07
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | roller | <= 5.0.1 |
| apache | roller | 4.0 |
| apache | roller | 4.0.1 |
| apache | roller | 5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://rollerweblogger.org/project/entry/apache_roller_5_0_2
- http://secunia.com/advisories/55862
- http://secunia.com/advisories/55877
- http://security.coverity.com/advisory/2013/Oct/remote-code-execution-in-apache-roller-via-ognl-injection.html
- http://www.exploit-db.com/exploits/29859
- http://www.osvdb.org/100342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89239
- http://rollerweblogger.org/project/entry/apache_roller_5_0_2
- http://secunia.com/advisories/55862
- http://secunia.com/advisories/55877
- http://security.coverity.com/advisory/2013/Oct/remote-code-execution-in-apache-roller-via-ognl-injection.html
- http://www.exploit-db.com/exploits/29859
- http://www.osvdb.org/100342
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89239
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-4212