PoC Index

CVE-2013-4212

MEDIUM 6.8EPSS 81.1%

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka "OGNL Injection."

CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
81.07% chance of exploitation in the next 30 days, 100th percentile
Published
2013-12-07
Updated
2024-08-06

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related