CVE-2011-5057
28Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendepss 29%
de la publicación al arma0 días
Publicada en NVD8 ene
1ª PoC7 dic
probabilidad de explotación
29%top 2% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."
Productos afectados
n/a · n/aPoCs públicas encontradas — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36426⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.