Количество 6
Количество 6
CVE-2016-4003
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.
CVE-2016-4003
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.
CVE-2016-4003
Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.
CVE-2016-4003
Cross-site scripting (XSS) vulnerability in the URLDecoder function in ...
GHSA-m3x6-9v6h-4g28
Cross-site Scripting in Apache Struts
BDU:2022-05819
Уязвимость реализации класса URLDecoder программной платформы Java Runtime Environment и средства разработки приложений Java Development Kit, позволяющая нарушителю проводить межсайтовые сценарные атаки
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-4003 Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter. | CVSS3: 6.1 | 3% Низкий | почти 10 лет назад | |
CVE-2016-4003 Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter. | CVSS2: 4.3 | 3% Низкий | почти 10 лет назад | |
CVE-2016-4003 Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter. | CVSS3: 6.1 | 3% Низкий | почти 10 лет назад | |
CVE-2016-4003 Cross-site scripting (XSS) vulnerability in the URLDecoder function in ... | CVSS3: 6.1 | 3% Низкий | почти 10 лет назад | |
GHSA-m3x6-9v6h-4g28 Cross-site Scripting in Apache Struts | CVSS3: 6.1 | 3% Низкий | больше 3 лет назад | |
BDU:2022-05819 Уязвимость реализации класса URLDecoder программной платформы Java Runtime Environment и средства разработки приложений Java Development Kit, позволяющая нарушителю проводить межсайтовые сценарные атаки | CVSS3: 6.1 | 3% Низкий | больше 10 лет назад |
Уязвимостей на страницу