Show filters
85 Total Results
Displaying 11-20 of 85
Sort by:
Attacker Value
Unknown

CVE-2019-0233

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Attacker Value
Unknown

CVE-2015-2992

Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2012-1592

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
Attacker Value
Unknown

CVE-2011-3923

Disclosure Date: November 01, 2019 (last updated November 08, 2023)
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
Attacker Value
Unknown

CVE-2018-1327

Disclosure Date: March 27, 2018 (last updated November 08, 2023)
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here http://struts.apache.org/plugins/rest/#custom-contenttypehandlers. Another option is to implement a custom XML handler based on the Jackson XML handler from the Apache Struts 2.5.16.
0
Attacker Value
Unknown

CVE-2017-15707

Disclosure Date: December 01, 2017 (last updated November 26, 2024)
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
0
Attacker Value
Unknown

CVE-2016-3090

Disclosure Date: October 30, 2017 (last updated November 26, 2024)
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
0
Attacker Value
Unknown

CVE-2016-4461

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.
0
Attacker Value
Unknown

CVE-2015-5169

Disclosure Date: September 25, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
0
Attacker Value
Unknown

CVE-2016-6795

Disclosure Date: September 20, 2017 (last updated November 26, 2024)
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.
0