Apache Struts是美国阿帕奇(Apache)软件基金会负责维护的一个开源项目,是一套用于创建企业级Java Web应用的开源MVC框架,主要提供两个版本框架产品,Struts 1和Struts 2。 Apache Struts 2.0.0至2.3.14.2版本中存在远程命令执行漏洞。远程攻击者可借助带有‘${}’和‘%{}’序列值(可导致判断OGNL代码两次)的请求,利用该漏洞执行任意OGNL代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2013-0245 | Drupal Book模块‘printer friendly version’功能权限许可和访问控制漏洞 | |
| CVE-2013-0246 | Drupal Image模块权限许可和访问控制漏洞 | |
| CVE-2013-1907 | Drupal Commons Group模块权限许可和访问控制漏洞 | |
| CVE-2013-1908 | Drupal Commons Wikis模块权限许可和访问控制漏洞 | |
| CVE-2013-1925 | Drupal Chaos Tool Suite模块访问绕过漏洞 | |
| CVE-2013-2122 | Drupal Edit Limit模块访问绕过漏洞 | |
| CVE-2013-2134 | Apache Struts 任意OGNL代码执行漏洞 | |
| CVE-2013-1943 | Linux kernel 输入验证错误漏洞 | |
| CVE-2013-1935 | Red Hat Enterprise Linux kernel KVM子系统拒绝服务漏洞 | |
| CVE-2013-2188 | Red Hat Enterprise Linux 内核软件‘do_filp_open’函数权限许可和访问控制漏洞 | |
| CVE-2013-3491 | WordPress Sharebar插件跨站请求伪造漏洞 | |
| CVE-2013-4117 | WordPress Category Grid View Gallery插件‘ID’参数跨站脚本漏洞 |
No comments yet