Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2014-0116
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
0
Attacker Value
Unknown
CVE-2013-4316
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2013-4310
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
0
Attacker Value
Unknown
CVE-2013-2248
Disclosure Date: July 20, 2013 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
0