Expression Language Injection
Stefano Di Paola <[email protected]>
| Newsgroups | gmane.comp.security.web-applications,gmane.comp.security.websecurity,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <1315824937.7997.146.camel@tucbook> |
Guys, someone may be interested in this Spring MVC related paper (CVE-2011-2730) "Expression Language Injection": http://blog.mindedsecurity.com/2011/09/expression-language-injection.html Vulnerable app and server side examples: http://68.169.49.40:18080/ELInjection/demo.htm Client side Poc example: http://www.wisec.it/spring/springopt.html Official fix/statement from SpringSource: http://www.springsource.com/security/cve-2011- Cheers, Stefano Ps. sorry for cross post :) -- ...oOOo...oOOo.... Stefano Di Paola Software & Security Engineer Owasp Italy R&D Director Web: www.wisec.it Twitter: http://twitter.com/WisecWisec Work: http://www.mindedsecurity.com Blog: http://blog.mindedsecurity.com .................. This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus --------------------------------------