Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-0838

Опубликовано: 02 мар. 2012
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 10

Описание

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code not present]]
hardy

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life

Показывать по

EPSS

Процентиль: 96%
0.1388
Средний

10 Critical

CVSS2

Связанные уязвимости

redhat
около 15 лет назад

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

nvd
больше 14 лет назад

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

debian
больше 14 лет назад

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expressio ...

github
около 4 лет назад

Apache Struts Code injection due to conversion error

CVSS3: 9.8
fstec
около 15 лет назад

Уязвимость программной платформы Apache Struts, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.1388
Средний

10 Critical

CVSS2