- EPSS 36.6%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 16.06.2026 23:02:20
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Obje...
CVE-2006-1548
- EPSS 5.33%
- Veröffentlicht 30.03.2006 22:02:00
- Zuletzt bearbeitet 16.06.2026 22:23:10
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via t...
CVE-2006-1547
- EPSS 54.64%
- Veröffentlicht 30.03.2006 22:02:00
- Zuletzt bearbeitet 16.06.2026 22:23:10
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHand...
CVE-2006-1546
- EPSS 6.14%
- Veröffentlicht 30.03.2006 22:02:00
- Zuletzt bearbeitet 16.06.2026 22:23:10
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from a...
CVE-2005-3745
- EPSS 25.71%
- Veröffentlicht 22.11.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:32
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler genera...