Security Advisory

CVE-2015-0254

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-03-09 14:00:00
Last updated 2024-08-06 04:03:10
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.