Описание
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libstruts1.2-java | not-affected | package |
Примечания
https://struts.apache.org/docs/s2-031.html
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 10 лет назад
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
CVSS3: 9.8
nvd
больше 10 лет назад
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
CVSS3: 9.8
fstec
больше 10 лет назад
Уязвимость реализации класса XSLTResult программной платформы Apache Struts, позволяющая нарушителю выполнить произвольный код