Description
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
Remediation
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2603)
WordPress Plugin Our Team Showcase Cross-Site Request Forgery (1.2)
Apache HTTP Server CVE-2009-1191 Vulnerability (CVE-2009-1191)
Sqlite Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-6607)
Chamilo Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-1999019)