13.07.2015 Views

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-<strong>2010</strong>-1622Incorrect usage of Beans API exposesorg.apache.catalina.loader.WebAppClassloader’sURL paths:class.classLoader.URLs[0]=file:///tmp/Overridden path isn’t used to resolve classesBut Jasper (Apache’s JSP engine) uses overridenpaths to resolve JSP tag libraries (TLD)Thursday, November 25, <strong>2010</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!