LWN.net Logo

JBoss: inject and execute arbitrary commands

Package(s):JBoss CVE #(s):CVE-2007-6306 CVE-2007-6433
Created:March 25, 2008 Updated:March 26, 2008
Description: The JFreeChart component was vulnerable to multiple cross-site scripting (XSS) vulnerabilities. An attacker could misuse the image map feature to inject arbitrary web script or HTML via several attributes of the chart area. The setOrder method in the org.jboss.seam.framework.Query class did not properly validate user-supplied parameters. This vulnerability allowed remote attackers to inject and execute arbitrary EJBQL commands via the order parameter.
Alerts:
Red Hat RHSA-2008:0158-01 2008-03-24

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds