Page 12 of 57 results (0.018 seconds)

CVSS: 5.0EPSS: 1%CPEs: 20EXPL: 4

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character. ParametersInterceptor en OpenSymphony XWork 2.0.x antes de 2.0.6 y 2.1.x antes de 2.1.2, tal como se utiliza en Apache Struts y otros productos, no restringe adecuadamente las referencias # (almohadilla) a objetos de contexto, lo que permite a atacantes remotos ejecutar sentencias OGNL (Object-Graph Navigation Language) y modificar los objetos del contexto del lado del servidor contexto objetos, como lo demuestra el uso de una representación \u0023 del carácter #. • https://www.exploit-db.com/exploits/32564 http://fisheye6.atlassian.com/cru/CR-9 http://issues.apache.org/struts/browse/WW-2692 http://jira.opensymphony.com/browse/XW-641 http://osvdb.org/49732 http://secunia.com/advisories/32495 http://secunia.com/advisories/32497 http://struts.apache.org/2.x/docs/s2-003.html http://www.securityfocus.com/bid/32101 http://www.vupen.com/english/advisories/2008/3003 http://www.vupen.com/english/advisories/2008/3004 https:&# • CWE-20: Improper Input Validation •

CVSS: 5.0EPSS: 96%CPEs: 7EXPL: 1

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x. Múltiples vulnerabilidades de salto de directorio en Apache Struts v2.0.x anteriores a v2.0.12 y v2.1.x anteriores a v2.1.3, permite a atacantes remotos leer ficheros de su elección a través de ..%25f (punto punto barra, codificado) en una dirección Web con /struts/ path, relativo a (1) FilterDispatcher en v2.0.x y (2)DefaultStaticContentLoader en v2.1.x. • https://www.exploit-db.com/exploits/32565 http://issues.apache.org/struts/browse/WW-2779 http://osvdb.org/49733 http://osvdb.org/49734 http://secunia.com/advisories/32497 http://struts.apache.org/2.x/docs/s2-004.html http://www.securityfocus.com/bid/32104 http://www.vupen.com/english/advisories/2008/3003 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •