Количество 6
Количество 6
CVE-2014-0116
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
CVE-2014-0116
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
CVE-2014-0116
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.
CVE-2014-0116
CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard ...
GHSA-hmhq-382q-mp56
ClassLoader manipulation in Apache Struts
BDU:2015-00403
Уязвимость реализации метода getClass класса CookieInterceptor программной платформы Apache Struts, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2014-0116 CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113. | CVSS2: 5.8 | 5% Низкий | больше 11 лет назад | |
CVE-2014-0116 CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113. | CVSS2: 5 | 5% Низкий | больше 11 лет назад | |
CVE-2014-0116 CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113. | CVSS2: 5.8 | 5% Низкий | больше 11 лет назад | |
CVE-2014-0116 CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard ... | CVSS2: 5.8 | 5% Низкий | больше 11 лет назад | |
GHSA-hmhq-382q-mp56 ClassLoader manipulation in Apache Struts | 5% Низкий | больше 3 лет назад | ||
BDU:2015-00403 Уязвимость реализации метода getClass класса CookieInterceptor программной платформы Apache Struts, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных | CVSS3: 6.1 | 5% Низкий | больше 11 лет назад |
Уязвимостей на страницу