CVE-2009-1088 Information

Description

Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with \extension elements and extension functions\ that trigger code execution by Xalan-Java as demonstrated using xalan://java.lang.Runtime.

Reference

http://support.hannonhill.com/browse/CSCD-4753 http://www.securityfocus.com/archive/1/501981/100/0/threaded http://www.securityfocus.com/bid/34186 https://exchange.xforce.ibmcloud.com/vulnerabilities/49332 https://www.exploit-db.com/exploits/8247

Share on: