Changes for page Application_Liferay

Last modified by Nicolas Gregoire on 2012/04/19 14:05

From version Icon 8.1 Icon
edited by Nicolas Gregoire
on 2012/01/13 14:05
Change comment: There is no comment for this version
To version Icon 5.1 Icon
edited by Nicolas Gregoire
on 2012/01/13 14:04
Change comment: There is no comment for this version

Summary

Details

Icon Page properties
Content
... ... @@ -14,15 +14,16 @@
14 14  
15 15  == Additional vulnerabilities ==
16 16  
17 -Two others vulnerabilities were identified in the "XSL Content" portlet :
18 18  
19 -* CVE-2011-1503 : allows to read XML files via a file:~/~/ URL
20 20  
21 -* CVE-2011-1502 : allows to read UTF-8 files and to list directories via a XEE (XML External Entity) attack
22 22  
23 23  
21 +Two others vulnerabilities were identified in the "XSL Content" portlet :
24 24  
23 +* CVE-2011-1503 : allows to read XML files via a file:~/~/ URL
25 25  
25 +* CVE-2011-1502 : allows to read UTF-8 files and to list directories via a XEE (XML External Entity) attack
26 +
26 26  Reading /etc/passwd using CVE-2011-1502 :
27 27  
28 28  [[image:liferay-read-etc-passwd-via-xee.png||style="display: block; margin-left: auto; margin-right: auto"]]