Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-0094

Опубликовано: 11 мар. 2014
Источник: nvd
CVSS2: 5
EPSS Критический

Описание

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.3.16.1 (исключая)

EPSS

Процентиль: 100%
0.99614
Критический

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
больше 12 лет назад

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

redhat
больше 12 лет назад

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

debian
больше 12 лет назад

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remo ...

github
около 4 лет назад

ClassLoader manipulation in Apache Struts

CVSS3: 4.7
fstec
больше 12 лет назад

Уязвимость реализации класса ParametersInterceptor программной платформы Apache Struts, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 100%
0.99614
Критический

5 Medium

CVSS2

Дефекты

NVD-CWE-noinfo