peter bassill · operator
$ cve CVE-2011-1571 JSON

CVE-2011-1571 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote attackers to execute arbitrary commands via unknown vectors.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS8.47% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2011-05-07
Last modified2026-06-16

Affected (1)

VendorProduct
liferayliferay portal

Public exploits

SourceTitleDate
exploit-dbLiferay XSL - Command Execution (Metasploit)2012-04-08

References

→ the Explorer  ·  watch your stack  ·  NVD