Show filters
85 Total Results
Displaying 11-20 of 85
Sort by:
Attacker Value
Unknown
CVE-2019-0233
Disclosure Date: September 14, 2020 (last updated February 22, 2025)
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
0
Attacker Value
Unknown
CVE-2015-2992
Disclosure Date: February 27, 2020 (last updated February 21, 2025)
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2012-1592
Disclosure Date: December 05, 2019 (last updated November 27, 2024)
A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files.
0
Attacker Value
Unknown
CVE-2011-3923
Disclosure Date: November 01, 2019 (last updated November 08, 2023)
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2018-1327
Disclosure Date: March 27, 2018 (last updated November 08, 2023)
The Apache Struts REST Plugin is using XStream library which is vulnerable and allow perform a DoS attack when using a malicious request with specially crafted XML payload. Upgrade to the Apache Struts version 2.5.16 and switch to an optional Jackson XML handler as described here http://struts.apache.org/plugins/rest/#custom-contenttypehandlers. Another option is to implement a custom XML handler based on the Jackson XML handler from the Apache Struts 2.5.16.
0
Attacker Value
Unknown
CVE-2017-15707
Disclosure Date: December 01, 2017 (last updated November 26, 2024)
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
0
Attacker Value
Unknown
CVE-2016-3090
Disclosure Date: October 30, 2017 (last updated November 26, 2024)
The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
0
Attacker Value
Unknown
CVE-2016-4461
Disclosure Date: October 16, 2017 (last updated November 26, 2024)
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.
0
Attacker Value
Unknown
CVE-2015-5169
Disclosure Date: September 25, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Apache Struts before 2.3.20.
0
Attacker Value
Unknown
CVE-2016-6795
Disclosure Date: September 20, 2017 (last updated November 26, 2024)
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.
0