看板 Bugtraq 關於我們 聯絡資訊
--Apple-Mail=_B47CE5B6-0B23-406C-8023-6F03CEF79315 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=iso-8859-1 CVE-2013-2250 - Apache OFBiz Nested expression evaluation allows remote = users to execute arbitrary UEL functions in OFBiz Vendor: The Apache Software Foundation Versions Affected: Apache OFBiz 10.04.01 to 10.04.05 Apache OFBiz 11.04.01 to 11.04.02 Apache OFBiz 12.04.01 Description: Parameter values are not correctly validated and if JUEL metacharacters = are included they are interpreted. Mitigation: 10.04.x users should upgrade to 10.04.06 11.04.x users should upgrade to 11.04.03 12.04.01 users should upgrade to 12.04.02 Credit: This issue was discovered by Gr=E9gory Draperi = (gregory.draperi@gmail.com). References: http://ofbiz.apache.org/download.html#vulnerabilities --Apple-Mail=_B47CE5B6-0B23-406C-8023-6F03CEF79315 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP using GPGMail -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.19 (Darwin) iQIcBAEBCgAGBQJR6rTGAAoJEHpYCQiEevngVXMP/1SjZEHXRBNyVjUp6dxoe6EZ 0INWM4bFYtQajaAhzuJmaWg0XpeXUw7RueSKnnAjMPFDS/e3GESEblW1sjL6stUl mX+XsOJUUduPaBFTRsJ4yXV/JCw7/CPW+IEtgbTHOw0ahBcQqUo+drFQH/9vfKC6 2VDJuo/RTm7EuF0Lc5wIYfaokZbpoNzWYwd9OUtIAPFvKKasnsLvbTEXlii8+xAo gqQbYJs7nYn1BRL9+03k2b0PMPNvCwue8ynVISdVelCeow9lehEiPOCq2xYMIiuz pCVUbs+Pd+W1z+7reAAlAuNkPMEVdC55FGsBr2Qe7K8P+IAgu26yFuDGH0D++4o6 cf2Wx1bbvBiRgrdoz3MQQosRKlhp14U7dtt3IV/rDqTPqPduDVAw9as0j1YtHVUa 01V7vKm4w5eRRcG8M8frwfelfj5kvjYP7mgWt/6ikItHY/qQS/1wBvACbyWi7fv8 8c110X++SUxVHqoSNMdoMCYT6/weGsPaBEia7uwB7+f8eYZ27XgjazUKdjeYLSt+ nwxtsXeTEInlEtA1NdlHnDbTQo67vFumAAFXB3/vxENVvMwGc3MEy5E5SlaAu9/O B/UH5aeRVThaoIS4j7s55S+cMNgvma+zMEWxAHaiOvWOANh8kVyJfsUYmrlKUYui 2yLWuT9d7qPu72YsepQy =yl5i -----END PGP SIGNATURE----- --Apple-Mail=_B47CE5B6-0B23-406C-8023-6F03CEF79315--