>> Sun Java System Access Manager XSLT Code Execution Vulnerability
Title : Sun Java System Access Manager XSLT Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-1967 CVE ID : CVE-2008-2945 CWE ID : CWE-20
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-06-30
Technical Description
A vulnerability has been identified in Sun Java System Access Manager, which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by an error when processing XSLT stylesheets embedded inside XSLT Transforms in XML Signatures, which could be exploited by attackers to execute arbitrary code via a malicious XML Signature.
Note: This issue only affects the XML signing functionality.