Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache struts 2.3.1.2 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2011-3923
Apache Struts prior to 2.3.1.2 allows remote malicious users to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.
Apache Struts
Redhat Jboss Enterprise Web Server 1.0.0
1 EDB exploit
1 Github repository
8.8
CVSSv3
CVE-2016-3090
The TextParseUtil.translateVariables method in Apache Struts 2.x prior to 2.3.20 allows remote malicious users to execute arbitrary code via a crafted OGNL expression with ANTLR tooling.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.3.5
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.1.0
Apache Struts 2.3.15
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.3.13
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.17
Apache Struts 2.3.9
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.1.3
Apache Struts 2.3.6
9.8
CVSSv3
CVE-2017-12611
In Apache Struts 2.0.0 up to and including 2.3.33 and 2.5 up to and including 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.5.9
Apache Struts 2.3.5
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.3.28
Apache Struts 2.1.0
Apache Struts 2.3.20.2
Apache Struts 2.5
Apache Struts 2.3.15
Apache Struts 2.3.25
Apache Struts 2.5.2
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.3.32
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.3.13
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.24.2
1 Github repository
1 Article
8.1
CVSSv3
CVE-2017-9805
The REST Plugin in Apache Struts 2.1.1 up to and including 2.3.x prior to 2.3.34 and 2.5.x prior to 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
Apache Struts 2.3.1.1
Apache Struts 2.5.9
Apache Struts 2.2.3.1
Apache Struts 2.3.28
Apache Struts 2.3.15
Apache Struts 2.5.2
Apache Struts 2.3.14
Apache Struts 2.3.32
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.5.10
Apache Struts 2.3.24.1
Apache Struts 2.5.6
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.1.3
Apache Struts 2.1.2
Apache Struts 2.1.5
Apache Struts 2.3.24.3
Apache Struts 2.3.15.2
1 EDB exploit
20 Github repositories
3 Articles
7.5
CVSSv3
CVE-2015-5209
Apache Struts 2.x prior to 2.3.24.1 allows remote malicious users to manipulate Struts internals, alter user sessions, or affect container settings via vectors involving a top object.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.3.5
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.1.0
Apache Struts 2.3.20.2
Apache Struts 2.3.15
Apache Struts 2.0.0
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.3.13
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.17
Apache Struts 2.3.22
Apache Struts 2.3.9
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
9.8
CVSSv3
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
Apache Struts 2.3.1.1
Apache Struts 2.3.28
Apache Struts 2.3.15
Apache Struts 2.3.14
Apache Struts 2.3.32
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.3.24.3
Apache Struts 2.3.15.2
Apache Struts 2.3.29
Apache Struts 2.3.14.3
Apache Struts 2.3.4.1
Apache Struts 2.3.20.1
Apache Struts 2.3.8
Apache Struts 2.3.30
Apache Struts 2.3.7
Apache Struts 2.3.24
Apache Struts 2.3.28.1
Apache Struts 2.3.14.2
2 EDB exploits
8 Github repositories
1 Article
9.8
CVSSv3
CVE-2016-4436
Apache Struts 2 prior to 2.3.29 and 2.5.x prior to 2.5.1 allow malicious users to have unspecified impact via vectors related to improper action name clean up.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.3.28
Apache Struts 2.5
Apache Struts 2.3.15
Apache Struts 2.0.0
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.3.24.3
Apache Struts 2.0.1
Apache Struts 2.3.15.2
5.3
CVSSv3
CVE-2016-3093
Apache Struts 2.0.0 up to and including 2.3.24.1 does not properly cache method references when used with OGNL prior to 3.0.12, which allows remote malicious users to cause a denial of service (block access to a web site) via unspecified vectors.
Ognl Project Ognl
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.10
Apache Struts 2.0.11
Apache Struts 2.0.11.1
Apache Struts 2.0.11.2
Apache Struts 2.0.12
Apache Struts 2.0.13
Apache Struts 2.0.14
Apache Struts 2.1.0
Apache Struts 2.1.1
Apache Struts 2.1.2
Apache Struts 2.1.3
9.8
CVSSv3
CVE-2016-3082
XSLTResult in Apache Struts 2.x prior to 2.3.20.2, 2.3.24.x prior to 2.3.24.2, and 2.3.28.x prior to 2.3.28.1 allows remote malicious users to execute arbitrary code via the stylesheet location parameter.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.3.28
Apache Struts 2.1.0
Apache Struts 2.3.15
Apache Struts 2.0.0
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.1.3
Apache Struts 2.1.2
Apache Struts 2.1.5
8.1
CVSSv3
CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote malicious users to execute arbitrary code via method: prefix, related to chained expressions.
Apache Struts 2.3.1.1
Apache Struts 2.0.9
Apache Struts 2.0.12
Apache Struts 2.2.3.1
Apache Struts 2.3.28
Apache Struts 2.1.0
Apache Struts 2.3.15
Apache Struts 2.0.0
Apache Struts 2.3.14
Apache Struts 2.0.8
Apache Struts 2.0.7
Apache Struts 2.0.4
Apache Struts 2.2.1
Apache Struts 2.3.16
Apache Struts 2.3.24.1
Apache Struts 2.1.8.1
Apache Struts 2.3.3
Apache Struts 2.3.16.3
Apache Struts 2.3.4
Apache Struts 2.1.3
Apache Struts 2.1.2
Apache Struts 2.1.5
1 EDB exploit
2 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »