Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-3923

Опубликовано: 01 нояб. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Высокий

Описание

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.3.1.2 (исключая)
Конфигурация 2
cpe:2.3:a:redhat:jboss_enterprise_web_server:1.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.88363
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

CVSS3: 9.8
debian
почти 7 лет назад

Apache Struts before 2.3.1.2 allows remote attackers to bypass securit ...

CVSS3: 9.8
github
больше 4 лет назад

Struts ParameterInterceptor vulnerability allows remote command execution

EPSS

Процентиль: 100%
0.88363
Высокий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-732