Описание
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.
Ссылки
- Vendor Advisory
- Third Party AdvisoryVDB EntryVendor Advisory
- Patch
- PatchThird Party Advisory
- Patch
- PatchThird Party Advisory
- Patch
- Patch
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue Tracking
- Issue TrackingPatch
- Third Party Advisory
- Third Party Advisory
- Patch
Уязвимые конфигурации
Одно из
EPSS
8.2 High
CVSS3
6.4 Medium
CVSS2
Дефекты
Связанные уязвимости
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not prop ...
Уязвимость программной платформы Apache Struts, позволяющая нарушителю вызвать отказ в обслуживании или провести XSS-атаки
EPSS
8.2 High
CVSS3
6.4 Medium
CVSS2