First published: Tue Dec 18 2007(Updated: )
The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands via the order parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jboss Seam | <=2.0.0 | |
JBoss Seam | <=2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.