vendor:
Struts
by:
SecurityFocus
7,5
CVSS
HIGH
Remote OGNL Expression Injection
94
CWE
Product Name: Struts
Affected Version From: 2.0.0
Affected Version To: 2.3.14.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Apache Struts Remote OGNL Expression Injection Vulnerability
Apache Struts is prone to a remote OGNL expression injection vulnerability. Remote attackers can exploit this issue to manipulate server-side objects and execute arbitrary commands within the context of the application.
Mitigation:
Users should upgrade to Apache Struts 2.3.15.1 or later.