Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
apache struts 2.3.24.3 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2016-4433
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request....
Apache Struts 2.3.20.1
Apache Struts 2.3.20
Apache Struts 2.3.28
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
Apache Struts 2.3.20.3
6.8
CVSSv2
CVE-2016-4430
Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors....
Apache Struts 2.3.28.1
Apache Struts 2.3.20
Apache Struts 2.3.20.3
Apache Struts 2.3.20.1
Apache Struts 2.3.28
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
5
CVSSv2
CVE-2016-4431
Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method....
Apache Struts 2.3.28
Apache Struts 2.3.20.1
Apache Struts 2.3.20
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
Apache Struts 2.3.20.3
7.5
CVSSv2
CVE-2016-4438
The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression....
Apache Struts 2.3.20
Apache Struts 2.3.20.3
Apache Struts 2.3.20.1
Apache Struts 2.3.28
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
5 Github repositories available
5
CVSSv2
CVE-2016-4465
The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field....
Apache Struts 2.5
Apache Struts 2.3.28.1
Apache Struts 2.3.20
Apache Struts 2.3.20.3
Apache Struts 2.3.20.1
Apache Struts 2.3.28
Apache Struts 2.3.24.3
Apache Struts 2.3.24.1
Apache Struts 2.3.24
7.5
CVSSv2
CVE-2016-6795
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side....
Apache Struts 2.3.20.2
Apache Struts 2.3.21
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.25
Apache Struts 2.3.26
Apache Struts 2.3.27
Apache Struts 2.3.24
Apache Struts 2.3.22
Apache Struts 2.3.23
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.24.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24.2
Apache Struts 2.3.24.3
3 Github repositories available
7.5
CVSSv2
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage....
Apache Struts 2.3.1
Apache Struts 2.3.1.1
Apache Struts 2.3.1.2
Apache Struts 2.3.3
Apache Struts 2.3.4
Apache Struts 2.3.4.1
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.12
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.16.3
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.20.3
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.24.3
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.3.32
2 EDB exploits available
1 Metasploit module available
43 Github repositories available
4 Articles available
5
CVSSv2
CVE-2017-9787
When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33....
Apache Struts 2.3.12
Apache Struts 2.3.13
Apache Struts 2.3.15.2
Apache Struts 2.3.15.3
Apache Struts 2.3.20.1
Apache Struts 2.3.20.2
Apache Struts 2.3.24.2
Apache Struts 2.3.24.3
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.3.32
Apache Struts 2.5.6
Apache Struts 2.5.7
Apache Struts 2.3.14
Apache Struts 2.3.14.1
Apache Struts 2.3.16
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.20.3
Apache Struts 2.3.21
Apache Struts 2.3.25
Apache Struts 2.3.26
Apache Struts 2.5
Apache Struts 2.5.1
Apache Struts 2.5.8
Apache Struts 2.5.9
Apache Struts 2.3.10
Apache Struts 2.3.11
Apache Struts 2.3.15
Apache Struts 2.3.15.1
Apache Struts 2.3.19
Apache Struts 2.3.20
Apache Struts 2.3.24
Apache Struts 2.3.24.1
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.5.4
Apache Struts 2.5.5
Apache Struts 2.3.7
Apache Struts 2.3.8
Apache Struts 2.3.9
Apache Struts 2.3.14.2
Apache Struts 2.3.14.3
Apache Struts 2.3.16.3
Apache Struts 2.3.17
Apache Struts 2.3.22
Apache Struts 2.3.23
Apache Struts 2.3.27
Apache Struts 2.3.28
Apache Struts 2.5.2
Apache Struts 2.5.3
Apache Struts 2.5.10
Apache Struts 2.5.10.1
2 Github repositories available
3 Articles available
5
CVSSv2
CVE-2017-9804
In Apache Struts 2.3.7 through 2.3.33 and 2.5 through 2.5.12, if an application allows entering a URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. ...
Apache Struts 2.5.12
Apache Struts 2.3.7
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.21
Apache Struts 2.3.22
Apache Struts 2.3.28.1
Apache Struts 2.3.29
Apache Struts 2.5
Apache Struts 2.5.7
Apache Struts 2.5.8
Apache Struts 2.3.10
Apache Struts 2.3.11
Apache Struts 2.3.12
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.19
Apache Struts 2.3.20
Apache Struts 2.3.25
Apache Struts 2.3.26
Apache Struts 2.3.32
Apache Struts 2.3.33
Apache Struts 2.5.3
Apache Struts 2.5.4
Apache Struts 2.3.8
Apache Struts 2.3.9
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.16.3
Apache Struts 2.3.17
Apache Struts 2.3.23
Apache Struts 2.3.24.2
Apache Struts 2.3.24.3
Apache Struts 2.3.30
Apache Struts 2.3.31
Apache Struts 2.5.1
Apache Struts 2.5.2
Apache Struts 2.5.9
Apache Struts 2.5.10
Apache Struts 2.5.10.1
Apache Struts 2.3.13
Apache Struts 2.3.14
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.20.1
Apache Struts 2.3.20.2
Apache Struts 2.3.27
Apache Struts 2.3.28
Apache Struts 2.5.5
Apache Struts 2.5.6
3 Github repositories available
4 Articles available
10
CVSSv2
CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type,...
Apache Struts 2.3.11
Apache Struts 2.3.12
Apache Struts 2.3.15.1
Apache Struts 2.3.15.2
Apache Struts 2.3.19
Apache Struts 2.3.20
Apache Struts 2.3.20.1
Apache Struts 2.3.24.1
Apache Struts 2.3.24.2
Apache Struts 2.3.29
Apache Struts 2.3.30
Apache Struts 2.3.10
Apache Struts 2.3.14.3
Apache Struts 2.3.15
Apache Struts 2.3.16.3
Apache Struts 2.3.17
Apache Struts 2.3.23
Apache Struts 2.3.24
Apache Struts 2.3.28
Apache Struts 2.3.28.1
Apache Struts 2.3.8
Apache Struts 2.3.9
Apache Struts 2.3.13
Apache Struts 2.3.14
Apache Struts 2.3.15.3
Apache Struts 2.3.16
Apache Struts 2.3.20.2
Apache Struts 2.3.20.3
Apache Struts 2.3.24.3
Apache Struts 2.3.25
Apache Struts 2.3.31
Apache Struts 2.3.5
Apache Struts 2.3.14.1
Apache Struts 2.3.14.2
Apache Struts 2.3.16.1
Apache Struts 2.3.16.2
Apache Struts 2.3.21
Apache Struts 2.3.22
Apache Struts 2.3.26
Apache Struts 2.3.27
Apache Struts 2.3.6
Apache Struts 2.3.7
Apache Struts 2.5.4
Apache Struts 2.5.6
Apache Struts 2.5.7
Apache Struts 2.5.10
Apache Struts 2.5.3
Apache Struts 2.5.5
Apache Struts 2.5.8
Apache Struts 2.5.9
Apache Struts 2.5
Apache Struts 2.5.1
Apache Struts 2.5.2
2 EDB exploits available
1 Metasploit module available
85 Github repositories available
6 Articles available
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
wireless
SQL
CVE-2023-1454
overflow
CVE-2022-48425
CVE-2023-25064
CVE-2023-28107
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »