Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2013-4316
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2013-4310
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
0
Attacker Value
Unknown
CVE-2013-2248
Disclosure Date: July 20, 2013 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
0
Attacker Value
Unknown
CVE-2012-4387
Disclosure Date: September 05, 2012 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
0
Attacker Value
Unknown
CVE-2012-4386
Disclosure Date: September 05, 2012 (last updated October 05, 2023)
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
0