vendor:
Liferay Portal
by:
drone
8,8
CVSS
HIGH
Pre-auth command injection
78
CWE
Product Name: Liferay Portal
Affected Version From: 7.0.0 M1
Affected Version To: 7.0.0 M3
Patch Exists: YES
Related CWE: N/A
CPE: //a:liferay:liferay_portal:7.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2014
Liferay Portal 7.0.0 M1, 7.0.0 M2, 7.0.0 M3 RCE
Pre-auth command injection using an exposed Apache Felix, exposed by default on all Liferay Portal 7.0 installs.
Mitigation:
Upgrade to Liferay Portal 7.0.3