CVE-2010-1622
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
- Affected products
- Spring Framework
- Oracle Fusion Middleware
- = 7.6.2, 11.1.1.6.1, 11.1.1.8.0
- Fix
- Available
- CVSS 2.0
- 6.0 MEDIUM
- EPSS
- 51.8% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2010-06-21
CVE-2010-1622 at NVD
14 known exploits for CVE-2010-1622
Proof-of-concept code and exploit modules indexed by Sploitus
Spring4Shell-PoC-exploit
cve-2010-1622_learning_environment
Spring-CVE-2010-1622
spring-shell-vuln
Exploit for Code Injection in Vmware Spring_Framework
Exploit for Code Injection in Vmware Spring_Framework
Exploit for Code Injection in Vmware Spring_Framework
Exploit for Code Injection in Vmware Spring_Framework
Exploit for Code Injection in Vmware Spring_Framework
Exploit for Code Injection in Oracle Fusion_Middleware
Spring Framework arbitrary code execution
Spring Framework class.classLoader类远程代码执行漏洞
Spring Framework - Arbitrary code Execution
Spring Framework - Arbitrary code Execution