6.8

CVE-2011-1571

Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Liferay ≫ Liferay Portal SwEdition community Version >= 5.1.0 <= 5.1.2
Liferay ≫ Liferay Portal SwEdition community Version >= 6.0.0 <= 6.0.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.47% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://openwall.com/lists/oss-security/2011/03/29/1
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2011/04/08/5
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2011/04/11/9
Third Party Advisory
Mailing List
http://issues.liferay.com/secure/ReleaseNote.jspa?version=10656&styleName=Html&projectId=10952
Vendor Advisory
Release Notes
http://issues.liferay.com/browse/LPS-14726
Vendor Advisory
Issue Tracking