Lucene search

K
prionPRIOn knowledge basePRION:CVE-2013-4212
HistoryDec 07, 2013 - 8:55 p.m.

Design/Logic Flaw

2013-12-0720:55:00
PRIOn knowledge base
www.prio-n.com
3

7.8 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka “OGNL Injection.”

CPENameOperatorVersion
rollereq4.0.1
rollerle5.0.1
rollereq4.0
rollereq5.0

7.8 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%