- EPSS 94.27%
- Published 11.03.2017 02:59:00
- Last modified 20.04.2025 01:37:25
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a...
CVE-2016-4436
- EPSS 6.12%
- Published 03.10.2016 15:59:01
- Last modified 12.04.2025 10:46:40
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.
CVE-2016-4465
- EPSS 13.34%
- Published 04.07.2016 22:59:10
- Last modified 12.04.2025 10:46:40
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.
CVE-2016-4438
- EPSS 53.5%
- Published 04.07.2016 22:59:09
- Last modified 12.04.2025 10:46:40
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
CVE-2016-4433
- EPSS 10.63%
- Published 04.07.2016 22:59:07
- Last modified 12.04.2025 10:46:40
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.
CVE-2016-4431
- EPSS 22.06%
- Published 04.07.2016 22:59:06
- Last modified 12.04.2025 10:46:40
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.
CVE-2016-4430
- EPSS 2.85%
- Published 04.07.2016 22:59:05
- Last modified 12.04.2025 10:46:40
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.
CVE-2016-1182
- EPSS 1.86%
- Published 04.07.2016 22:59:02
- Last modified 12.04.2025 10:46:40
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related iss...
CVE-2016-1181
- EPSS 6.13%
- Published 04.07.2016 22:59:01
- Last modified 12.04.2025 10:46:40
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart reques...
CVE-2015-0899
- EPSS 86.91%
- Published 04.07.2016 22:59:00
- Last modified 12.04.2025 10:46:40
The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.