7.5
CVSSv2

CVE-2007-6433

Published: 18/12/2007 Updated: 08/03/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x prior to 2.0.0.CR3 allows remote malicious users to inject and execute arbitrary EJBQL commands via the order parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

jboss seam