Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2016-4438
Disclosure Date: July 04, 2016 (last updated November 25, 2024)
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
0
Attacker Value
Unknown
CVE-2016-4433
Disclosure Date: July 04, 2016 (last updated November 25, 2024)
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
0
Attacker Value
Unknown
CVE-2016-4465
Disclosure Date: July 04, 2016 (last updated November 25, 2024)
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
0
Attacker Value
Unknown
CVE-2016-3093
Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-3087
Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
0
Attacker Value
Unknown
CVE-2016-3081
Disclosure Date: April 26, 2016 (last updated November 25, 2024)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
0
Attacker Value
Unknown
CVE-2016-3082
Disclosure Date: April 26, 2016 (last updated November 25, 2024)
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
0
Attacker Value
Unknown
CVE-2016-2162
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
0