Back to search
CVE-2007-6433
Published: Dec 18, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands via the order parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
RHSA-2008:0213
vendor-advisory
x_refsource_REDHAT
RHSA-2008:0151
vendor-advisory
x_refsource_REDHAT
http://jira.jboss.com/jira/browse/JBSEAM-2084
x_refsource_CONFIRM
26850
vdb-entry
x_refsource_BID
42631
vdb-entry
x_refsource_OSVDB
ADV-2007-4215
vdb-entry
x_refsource_VUPEN
RHSA-2008:0158
vendor-advisory
x_refsource_REDHAT
28077
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now