cve/2015/CVE-2015-0254.md
2024-06-18 02:51:15 +02:00

941 B

CVE-2015-0254

Description

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.

POC

Reference

Github