Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2013-4316

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2013-4310

Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
0
Attacker Value
Unknown

CVE-2013-2248

Disclosure Date: July 20, 2013 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
0
Attacker Value
Unknown

CVE-2012-4387

Disclosure Date: September 05, 2012 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processed as an OGNL expression.
0
Attacker Value
Unknown

CVE-2012-4386

Disclosure Date: September 05, 2012 (last updated October 05, 2023)
The token check mechanism in Apache Struts 2.0.0 through 2.3.4 does not properly validate the token name configuration parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks by setting the token name configuration parameter to a session attribute.
0