Link | Resource |
---|---|
https://www.vmware.com/security/advisories/VMSA-2020-0010.html | Vendor Advisory |
https://citadelo.com/en/blog/full-infrastructure-takeover-of-vmware-cloud-director-CVE-2020-3956/ | Exploit Third Party Advisory |
https://github.com/aaronsvk/CVE-2020-3956 | Exploit Third Party Advisory |
http://packetstormsecurity.com/files/157909/vCloud-Director-9.7.0.15498291-Remote-Code-Execution.html | Exploit Third Party Advisory |
Configuration 1
|
Published : 2020-05-20 02:15
Updated : 2021-12-13 07:07
NVD link : CVE-2020-3956
Mitre link : CVE-2020-3956
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')