Remote Code Execution With EL Injection Vulnerabiltiies

Discussion in 'News Aggregator' started by Packet Storm, 2 Feb 2019.

  1. Packet Storm

    Packet Storm Guest

    This paper discusses a vulnerability class called "Expression Language Injection (EL Injection)". Although several security researchers have published details in the past, the bug class is still fairly unknown. EL Injection is a serious security threat over the Internet for the various dynamic applications. In today's world, there is a universal need present for dynamic applications. As the use of dynamic applications for various online services is rising, so is the security threats increasing. This paper defines a methodology for detecting and exploiting EL injection.

    Continue reading...
     

Share This Page

Loading...