Описание
Code injection in Apache Struts
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-4316
- https://github.com/apache/struts/commit/58947c3f85ae641c1a476316a2888e53605948d1
- https://github.com/apache/struts/commit/c643336945dda84cbcdc8a39530baa24fede28c4
- http://archives.neohapsis.com/archives/bugtraq/2013-09/0107.html
- http://struts.apache.org/release/2.3.x/docs/s2-019.html
Пакеты
org.apache.struts:struts2-core
>= 2.0.0, < 2.3.15.2
2.3.15.2
org.apache.struts:struts2-rest-plugin
>= 2.0.0, < 2.3.15.2
2.3.15.2
Связанные уязвимости
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation ...
Уязвимость реализации механизма Dynamic Method Invocation (DMI) программной платформы Apache Struts, позволяющая нарушителю выполнить произвольный код