PublicCVE

CVE-2010-1622

UNRATEDRemote code exec
ExploitHigh EPSS

Description

SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.

Exploits & proofs of concept

Updated 9m ago · 8 sources