Show filters
85 Total Results
Displaying 41-50 of 85
Sort by:
Attacker Value
Unknown

CVE-2016-3081

Disclosure Date: April 26, 2016 (last updated November 25, 2024)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
0
Attacker Value
Unknown

CVE-2016-3082

Disclosure Date: April 26, 2016 (last updated November 25, 2024)
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
0
Attacker Value
Unknown

CVE-2016-4003

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.
0
Attacker Value
Unknown

CVE-2016-2162

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.
0
Attacker Value
Unknown

CVE-2016-0785

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.
0
Attacker Value
Unknown

CVE-2015-1831

Disclosure Date: July 16, 2015 (last updated October 05, 2023)
The default exclude patterns (excludeParams) in Apache Struts 2.3.20 allow remote attackers to "compromise internal state of an application" via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7809

Disclosure Date: December 10, 2014 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF protection mechanism.
0
Attacker Value
Unknown

CVE-2014-0116

Disclosure Date: May 08, 2014 (last updated October 05, 2023)
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
0
Attacker Value
Unknown

CVE-2014-0114

Disclosure Date: April 30, 2014 (last updated October 05, 2023)
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.
0
Attacker Value
Unknown

CVE-2014-0112

Disclosure Date: April 29, 2014 (last updated October 05, 2023)
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
0