CVE-2007-6726
- EPSS 1.5%
- Veröffentlicht 09.04.2009 15:08:35
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_...
- EPSS 57.52%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatch...
- EPSS 65.08%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Obje...
CVE-2006-1548
- EPSS 8.77%
- Veröffentlicht 30.03.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in (1) LookupDispatchAction and possibly (2) DispatchAction and (3) ActionDispatcher in Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to inject arbitrary web script or HTML via t...
CVE-2006-1547
- EPSS 13.58%
- Veröffentlicht 30.03.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHand...
CVE-2006-1546
- EPSS 1.61%
- Veröffentlicht 30.03.2006 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Apache Software Foundation (ASF) Struts before 1.2.9 allows remote attackers to bypass validation via a request with a 'org.apache.struts.taglib.html.Constants.CANCEL' parameter, which causes the action to be canceled but would not be detected from a...
CVE-2005-3745
- EPSS 55.84%
- Veröffentlicht 22.11.2005 11:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler genera...