SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  RichFaces Framework Expression Language Injection

Category: WEB-ATTACKS      

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via crafted request. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects.


Relevant Information