Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12611

Опубликовано: 20 сент. 2017
Источник: debian

Описание

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libstruts1.2-javaremovedpackage
libstruts1.2-javaignoredwheezypackage

Примечания

  • Only a problem if the application programmer has made a security mistake.

  • https://struts.apache.org/docs/s2-053.html

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

CVSS3: 8.1
redhat
почти 9 лет назад

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

CVSS3: 9.8
nvd
почти 9 лет назад

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

CVSS3: 9.8
github
почти 8 лет назад

Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal

CVSS3: 7.3
fstec
почти 9 лет назад

Уязвимость пакета Freemaker программной платформы Apache Struts, позволяющая нарушителю выполнить произвольный код