Show filters
85 Total Results
Displaying 31-40 of 85
Sort by:
Attacker Value
Unknown

CVE-2016-4430

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-4431

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.
0
Attacker Value
Unknown

CVE-2016-1182

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.
0
Attacker Value
Unknown

CVE-2016-1181

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
0
Attacker Value
Unknown

CVE-2015-0899

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.
0
Attacker Value
Unknown

CVE-2016-4438

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
0
Attacker Value
Unknown

CVE-2016-4433

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
0
Attacker Value
Unknown

CVE-2016-4465

Disclosure Date: July 04, 2016 (last updated November 25, 2024)
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
0
Attacker Value
Unknown

CVE-2016-3093

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-3087

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.
0