Apache Struts是美国阿帕奇(Apache)软件基金会的一个开源项目,是一套用于创建企业级Java Web应用的开源MVC框架,主要提供两个版本框架产品,Struts 1和Struts 2。 Apache Struts 2.0.0至2.3.14版本中存在代码注入漏洞,该漏洞源于程序没有充分处理用户提交的输入。攻击者可利用该漏洞以运行受影响应用程序用户的权限操控服务器端上下文对象,可完全控制应用程序和底层计算机。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A proof of concept exploit for the CVE-2013-1965 vulnerability affecting Apache Struts 2 | https://github.com/cinno/CVE-2013-1965 | POC Details |
| 2 | Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2013/CVE-2013-1965.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2013-3133 | Microsoft .NET Framework 匿名方法注入漏洞 | |
| CVE-2013-3171 | Microsoft .NET Framework 委派序列化漏洞 | |
| CVE-2013-3166 | Microsoft Internet Explorer Shift JIS 字符编码漏洞 | |
| CVE-2013-3148 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-3147 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-3146 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-3145 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-3144 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-3143 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-3134 | Microsoft .NET Framework 数组分配漏洞 | |
| CVE-2013-3149 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-3132 | Microsoft .NET Framework 委派反射绕过漏洞 | |
| CVE-2013-3131 | Microsoft .NET Framework 数组访问冲突漏洞 | |
| CVE-2013-3129 | Microsoft 多款产品代码注入漏洞 | |
| CVE-2013-3127 | Microsoft WMV 视频解码器远程执行代码漏洞 | |
| CVE-2013-3115 | Microsoft Internet Explorer 内存损坏漏洞 | |
| CVE-2013-1345 | Microsoft Windows Win32k 安全漏洞 | |
| CVE-2013-1340 | Microsoft Windows Win32k 解除引用漏洞 | |
| CVE-2013-1300 | Microsoft Windows Win32k 内存分配漏洞 | |
| CVE-2013-3350 | Adobe ColdFusion 安全绕过漏洞 |
Showing top 20 of 71 CVEs. View all on vendor page → →
No comments yet