Web Hack List

Collected research

Autobinding vulns and Spring MVC

Spring MVC repopulates an object taken from the model, session or a flash attribute with matching HTTP parameters, so a controller expecting trusted data can be rewritten by extra request parameters. That yields expression language injection, overwriting a security answer to reset another user's password, and session variable overloading.

Record

Published by
agrrrdog.blogspot.com
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of agrrrdog.blogspot.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .