// For flags

CVE-2007-4556

 

Severity Score

6.3
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.

Struts apoyado en OpenSymphony XWork anterior a 1.2.3, y 2.x anterior a 2.0.4, tal y como se utiliza en WebWork y Apache Struts, recursivamente evalua todas las entradas como una expresión Object-Graph Navigation Language (OGNL) cuando altSyntax está activado, lo cual permite a atacantes remotos provocar denegación de servicio (bucle infinito) o ejecutar código de su elección a través de un formulario de entradad comenzando con una secuencia "%{" y finalizando con un caracter "}".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-08-27 CVE Reserved
  • 2007-08-28 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opensymphony
Search vendor "Opensymphony"
Xwork
Search vendor "Opensymphony" for product "Xwork"
< 1.2.3
Search vendor "Opensymphony" for product "Xwork" and version " < 1.2.3"
-
Affected
Opensymphony
Search vendor "Opensymphony"
Xwork
Search vendor "Opensymphony" for product "Xwork"
>= 2.0.0 <= 2.0.4
Search vendor "Opensymphony" for product "Xwork" and version " >= 2.0.0 <= 2.0.4"
-
Affected