漏洞描述
A struts-based OGNL remote code execution vulnerability exists in ListSERV Maestro before and including version 9.0-8.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.securifera.comhttps://www.securifera.com/advisories/sec-2020-0001/↗packetstormsecurity.comhttps://packetstormsecurity.com/files/159643/listservmaestro-exec.txt↗confluence.atlassian.comhttp://confluence.atlassian.com/display/FISHEYE/FishEye+Security+Advisory+2010-06-16↗blog.o0o.nuhttp://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html↗