Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
Using QL to find a remote code execution vulnerability in Apache Struts | Better HN
Using QL to find a remote code execution vulnerability in Apache Struts
(opens in new tab)
(lgtm.com)
1 points
mossity
8y ago
1 comments
Share
1 comments
default
newest
oldest
mossity
OP
8y ago
Reading about CVE-2017-9805 it was really interesting to learn that the company that discovered it was using a Datalog-like language in order to query Java code for vulnerability patterns.
https://en.wikipedia.org/wiki/Semmle
j
/
k
navigate · click thread line to collapse