Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x prior to 2.0.11.1 and 2.1.x prior to 2.1.1 allow remote malicious users to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
apache struts 2.0.6 |
||
apache struts 2.0.8 |
||
apache struts 2.0.9 |
||
apache struts 2.0.11 |
||
apache struts 2.1 |