Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6795

Опубликовано: 20 сент. 2017
Источник: debian
EPSS Средний

Описание

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libstruts1.2-javaremovedpackage
libstruts1.2-javaend-of-lifewheezypackage

Примечания

  • https://struts.apache.org/docs/s2-042.html

EPSS

Процентиль: 94%
0.12481
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.

CVSS3: 9.8
nvd
больше 8 лет назад

In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.

CVSS3: 9.8
github
больше 3 лет назад

Path Traversal in Apache Struts

EPSS

Процентиль: 94%
0.12481
Средний