Back to search
CVE-2015-0249
Published: Jul 14, 2017
Modified: Aug 6, 2024
PUBLISHED
Description
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20150330 Fwd: CVE-2015-0249: Apache Roller allows admin users to execute arbitrary Java code
mailing-list
x_refsource_MLIST
http://cve.killedkenny.io/cve/CVE-2015-0249
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now