Collected research
EL 3.0/Lambda Injection: Hacker Friendly Java
Java EL3 implicitly exposes java.lang classes, allowing injected expressions to access system properties or execute commands without custom imports. Its semicolon operator chains expressions, extending exploitation to partially controlled expressions. The post gives servlet examples and identifies ELProcessor evaluation as a review target.
Record
- Researcher
- Shay Chen
- Published by
- Security Tools Benchmarking
- Date
- Topic
- Injection
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Shay Chen, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .