Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9cjh-qmvx-436c

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью

Описание

Apache Struts Cross-site scripting Vulnerability

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

Пакеты

Наименование

org.apache.struts:struts-core

maven
Затронутые версииВерсия исправления

<= 1.2.7

Отсутствует

EPSS

Процентиль: 98%
0.25707
Средний

Дефекты

CWE-80

Связанные уязвимости

ubuntu
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

redhat
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

nvd
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

debian
больше 20 лет назад

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and p ...

EPSS

Процентиль: 98%
0.25707
Средний

Дефекты

CWE-80