CVE-2011-1571: Command Injection
Published May 7, 2011
·Updated
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
Affected Software
3 affected componentsFixes available
Liferay Liferay Portal>=5.1.0<=5.1.2
Liferay Liferay Portal>=6.0.0<=6.0.5
maven/com.liferay.portal:portal-service>=5.0.0<6.0.6-ga
6.0.6-ga
Event History
May 7, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityAffected Software
May 13, 2022
Advisory Published
via GitHub·01:25 AM
Data Sourced
via GitHub·01:25 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-1571?
CVE-2011-1571 is considered a critical severity vulnerability due to its potential to allow remote command execution.
2
How do I fix CVE-2011-1571?
To fix CVE-2011-1571, upgrade Liferay Portal Community Edition to version 6.0.6 GA or later.
3
Which versions of Liferay are affected by CVE-2011-1571?
CVE-2011-1571 affects Liferay Portal Community Edition versions 5.x and 6.x prior to 6.0.6 GA.
4
What type of vulnerability is CVE-2011-1571?
CVE-2011-1571 is a remote command execution vulnerability that occurs when using Apache Tomcat.
5
Can CVE-2011-1571 be exploited without authentication?
Yes, CVE-2011-1571 can be exploited by remote attackers without requiring authentication.