Looking for the vulnerability index of Invicti's legacy products?
Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0248) - Vulnerability Database

Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-0248)

Description

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.

References

Related Vulnerabilities