Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2018-20059

Disclosure Date: December 11, 2018 (last updated November 27, 2024)
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
0
Attacker Value
Unknown

CVE-2017-18349

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.
0
Attacker Value
Unknown

CVE-2018-18628

Disclosure Date: October 23, 2018 (last updated November 27, 2024)
An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie. Sending this cookie may lead to remote code execution.
0