CWE-917
206 CVEs • Abstraction: Base
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CVEs (206)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earli...Show more |
An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of t...Show more |
1Sonatype 1Nexus Repository Manager Nov 21, 2024 Nov 15, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection. |
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit....Show more |
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, a...Show more |
2Netapp Redhat4Jboss Enterprise Application Platform Oncommand BalanceOncommand Insight+1 moreApr 22, 2026 Aug 5, 2010 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to exe...Show more |