Описание
Apache Struts's DebuggingInterceptor component allows remote code execution in developer mode
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2012-0394
- https://github.com/apache/struts/commit/34c80dae734e70f13c0e46f9c83602fb71318e58
- https://github.com/apache/struts/commit/9cad25f258bb2629d263f828574d2671366c238d
- https://issues.apache.org/jira/browse/WW-3729
- https://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical_Vulnerabilities.txt
- http://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html
- http://struts.apache.org/2.x/docs/s2-008.html
- http://struts.apache.org/2.x/docs/version-notes-2311.html
- http://www.exploit-db.com/exploits/18329
- http://www.exploit-db.com/exploits/31434
Пакеты
org.apache.struts.xwork:xwork-core
< 2.3.18
2.3.18
Связанные уязвимости
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself.
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, wh ...