"XWork是一个命令模式框架,用于支持Struts 2及其他应用。 如果启用了altSyntax功能的话,XWork就允许向文本字符串中注入OGNL表达式并递归的处理。远程攻击者可以通过HTML文本字段提交字符串,并在其中包含OGNL表达式,如果表单验证失败的话就会执行该表达式。例如,如果以下表单要求phoneNumber字段为非空的话: <s:form action="editUser"> <s:textfield name="name" /> <s:textfield name="phoneNumb
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Apache Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via for"m input beginning with a "%{" sequence and ending with a "}" character. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2007/CVE-2007-4556.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2007-4560 | ClamAV Popen Function 远程代码执行漏洞 | |
| CVE-2007-4580 | Trustware BufferZone 缓冲区溢出漏洞 | |
| CVE-2007-4578 | Sophos Antivirus UPX文件解析拒绝服务漏洞 | |
| CVE-2007-4577 | Sophos Antivirus BZIP文件解析拒绝服务漏洞 | |
| CVE-2007-3846 | Subversion for Windows Remote 目录遍历漏洞 | |
| CVE-2007-4566 | SIDVault Simple_Bind函数多个远程栈溢出漏洞 | |
| CVE-2007-4565 | Fetchmail无效警告消息本地拒绝服务漏洞 | |
| CVE-2007-4564 | Hitachi Cosminexus Application Server 多个授权访问漏洞 | |
| CVE-2007-4563 | Hitachi Cosminexus Application Server 多个授权访问漏洞 | |
| CVE-2007-4562 | Hitachi DABroker拒绝服务漏洞 | |
| CVE-2007-4561 | Real Networks Helix服务器RTSP命令远程堆溢出漏洞 | |
| CVE-2007-4549 | ALPass Import Site Information 缓冲区溢出漏洞 | |
| CVE-2007-4557 | Novell GroupWise WebAccess 跨站脚本攻击漏洞 | |
| CVE-2007-4521 | Asterisk畸形MIME体远程拒绝服务漏洞 | |
| CVE-2006-7222 | Media Player Classic FLI文件处理远程缓冲区溢出漏洞 | |
| CVE-2007-4559 | Python tarfile 模块路径遍历漏洞 | |
| CVE-2007-4555 | Ipswitch WS_FTP 跨站脚本攻击漏洞 | |
| CVE-2007-4554 | TikiWiki tiki-remind_password.php文件跨站脚本漏洞 | |
| CVE-2007-4553 | Thomson ST SIP phone拒绝服务漏洞 | |
| CVE-2007-4552 | RETIRED: Arcadem Index.PHP SQL注入漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet