CVE-2010-5327
published 2017-01-13CVE-2010-5327: Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
PriorityP355high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.73%
84.5th percentile
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| liferay | liferay_portal | <= 6.2.10 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Shell command injection in Liferay Portal
osv·2022-05-17
CVE-2010-5327 [HIGH] Shell command injection in Liferay Portal
Shell command injection in Liferay Portal
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
GHSA
Shell command injection in Liferay Portal
ghsa·2022-05-17
CVE-2010-5327 [HIGH] Shell command injection in Liferay Portal
Shell command injection in Liferay Portal
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://dev.liferay.com/web/community-security-team/known-vulnerabilitieshttps://dev.liferay.com/web/community-security-team/known-vulnerabilities/-/asset_publisher/4AHAYapUm8Xc/content/lps-64547-remote-code-execution-and-privilege-escalation-in-templateshttps://github.com/liferay/liferay-portal/commit/90c4e85a8f8135f069f3f05e4d54a77704769f91https://issues.liferay.com/browse/LPE-14964https://issues.liferay.com/browse/LPS-64547https://issues.liferay.com/browse/LPS-7087https://dev.liferay.com/web/community-security-team/known-vulnerabilitieshttps://dev.liferay.com/web/community-security-team/known-vulnerabilities/-/asset_publisher/4AHAYapUm8Xc/content/lps-64547-remote-code-execution-and-privilege-escalation-in-templateshttps://github.com/liferay/liferay-portal/commit/90c4e85a8f8135f069f3f05e4d54a77704769f91https://issues.liferay.com/browse/LPE-14964https://issues.liferay.com/browse/LPS-64547https://issues.liferay.com/browse/LPS-7087
2017-01-13
Published