Wieland wieplan 4.1 Document Parsing Java Code Execution Using XMLDecoder

Discussion in 'News Aggregator' started by Packet Storm, 12 Feb 2016.

  1. Packet Storm

    Packet Storm Guest

    Wieland wieplan version 4.1 suffers from an arbitrary java code execution when parsing WIE documents that uses XMLDecoder, allowing system access to the affected machine. The software is used to generate custom specification order saved in .wie XML file that has to be sent to the vendor offices to be processed.

    Continue reading...
     

Share This Page

Loading...