Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0116

Опубликовано: 08 мая 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 5.8

Описание

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
lucid

not-affected

precise

not-affected

quantal

not-affected

saucy

not-affected

trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

not-affected

Показывать по

5.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.

nvd
больше 11 лет назад

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.

debian
больше 11 лет назад

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard ...

github
больше 3 лет назад

ClassLoader manipulation in Apache Struts

CVSS3: 6.1
fstec
больше 11 лет назад

Уязвимость реализации метода getClass класса CookieInterceptor программной платформы Apache Struts, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

5.8 Medium

CVSS2