Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-0393

Опубликовано: 08 янв. 2012
Источник: nvd
CVSS2: 6.4
EPSS Средний

Описание

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
Версия от 2.1.0 (включая) до 2.3.1.1 (исключая)

EPSS

Процентиль: 98%
0.37185
Средний

6.4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 14 лет назад

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.

redhat
больше 14 лет назад

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.

debian
больше 14 лет назад

The ParameterInterceptor component in Apache Struts before 2.3.1.1 doe ...

github
больше 4 лет назад

Apache Struts's ParameterInterceptor component does not prevent access to public constructors

CVSS3: 7.2
fstec
больше 14 лет назад

Уязвимость компонента ParameterInterceptor программной платформы Apache Struts, позволяющая нарушителю записывать произвольные файлы в систему

EPSS

Процентиль: 98%
0.37185
Средний

6.4 Medium

CVSS2

Дефекты

CWE-264