The DiskFileItem class in Apache Wicket 6.x prior to 6.25.0 and 1.5.x prior to 1.5.17 allows remote malicious users to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM prior to 1.3.1, execute arbitrary code via a crafted serialized Java object.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apache wicket |