Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cjh-qmvx-436c

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью

Описание

Apache Struts Cross-site scripting Vulnerability

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

Пакеты

Наименование

org.apache.struts:struts-core

maven
Затронутые версииВерсия исправления

<= 1.2.7

Отсутствует

EPSS

Процентиль: 98%
0.55839
Средний

Дефекты

CWE-80

Связанные уязвимости

ubuntu
почти 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

redhat
почти 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

nvd
почти 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

debian
почти 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and p ...

EPSS

Процентиль: 98%
0.55839
Средний

Дефекты

CWE-80