CVE-2011-4343
08.08.2017, 21:29
Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.Enginsight
Vendor | Product | Version |
---|---|---|
apache | myfaces | 2.0.1 |
apache | myfaces | 2.0.2 |
apache | myfaces | 2.0.3 |
apache | myfaces | 2.0.4 |
apache | myfaces | 2.0.5 |
apache | myfaces | 2.0.6 |
apache | myfaces | 2.0.7 |
apache | myfaces | 2.0.8 |
apache | myfaces | 2.0.9 |
apache | myfaces | 2.0.10 |
apache | myfaces | 2.1.0 |
apache | myfaces | 2.1.1 |
apache | myfaces | 2.1.2 |
apache | myfaces | 2.1.3 |
apache | myfaces | 2.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References