Show filters
85 Total Results
Displaying 51-60 of 85
Sort by:
Attacker Value
Unknown
CVE-2014-0113
Disclosure Date: April 29, 2014 (last updated October 05, 2023)
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
0
Attacker Value
Unknown
CVE-2014-0094
Disclosure Date: March 11, 2014 (last updated October 05, 2023)
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
0
Attacker Value
Unknown
CVE-2013-6348
Disclosure Date: November 02, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.
0
Attacker Value
Unknown
CVE-2013-4316
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2013-4310
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
0
Attacker Value
Unknown
CVE-2013-2251
Disclosure Date: July 20, 2013 (last updated July 17, 2024)
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
0
Attacker Value
Unknown
CVE-2013-2248
Disclosure Date: July 20, 2013 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.
0
Attacker Value
Unknown
CVE-2013-2134
Disclosure Date: July 16, 2013 (last updated October 05, 2023)
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
0
Attacker Value
Unknown
CVE-2013-2135
Disclosure Date: July 16, 2013 (last updated October 05, 2023)
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.
0
Attacker Value
Unknown
CVE-2013-2115
Disclosure Date: July 10, 2013 (last updated November 25, 2024)
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.
0