Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-p66x-2cv9-qq3v

около 6 лет назад

Arbitrary code execution in Apache Commons BeanUtils

EPSS: Критический
ubuntu логотип

CVE-2014-0114

больше 12 лет назад

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVSS2: 7.5
EPSS: Критический
redhat логотип

CVE-2014-0114

больше 12 лет назад

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVSS2: 7.5
EPSS: Критический
nvd логотип

CVE-2014-0114

больше 12 лет назад

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVSS2: 7.5
EPSS: Критический
debian логотип

CVE-2014-0114

больше 12 лет назад

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8. ...

CVSS2: 7.5
EPSS: Критический
oracle-oval логотип

ELSA-2014-0474

около 12 лет назад

ELSA-2014-0474: struts security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2015-04139

больше 12 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
EPSS: Критический
fstec логотип

BDU:2015-00729

почти 12 лет назад

Уязвимость программного обеспечения WebLogic Server, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
EPSS: Критический
suse-cvrf логотип

SUSE-SU-2015:0886-1

около 12 лет назад

Security update for struts

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02056-1

около 1 года назад

Security update for apache-commons-beanutils

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-p66x-2cv9-qq3v

Arbitrary code execution in Apache Commons BeanUtils

96%
Критический
около 6 лет назад
ubuntu логотип
CVE-2014-0114

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVSS2: 7.5
96%
Критический
больше 12 лет назад
redhat логотип
CVE-2014-0114

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVSS2: 7.5
96%
Критический
больше 12 лет назад
nvd логотип
CVE-2014-0114

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

CVSS2: 7.5
96%
Критический
больше 12 лет назад
debian логотип
CVE-2014-0114

Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8. ...

CVSS2: 7.5
96%
Критический
больше 12 лет назад
oracle-oval логотип
ELSA-2014-0474

ELSA-2014-0474: struts security update (IMPORTANT)

около 12 лет назад
fstec логотип
BDU:2015-04139

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
96%
Критический
больше 12 лет назад
fstec логотип
BDU:2015-00729

Уязвимость программного обеспечения WebLogic Server, позволяющая удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
96%
Критический
почти 12 лет назад
suse-cvrf логотип
SUSE-SU-2015:0886-1

Security update for struts

около 12 лет назад
suse-cvrf логотип
SUSE-SU-2025:02056-1

Security update for apache-commons-beanutils

около 1 года назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.