5
CVSSv2

CVE-2011-2088

Published: 13/05/2011 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

XWork 2.2.1 in Apache Struts 2.2.1, and OpenSymphony XWork in OpenSymphony WebWork, allows remote malicious users to obtain potentially sensitive information about internal Java class paths via vectors involving an s:submit element and a nonexistent method, a different vulnerability than CVE-2011-1772.3.

Vulnerable Product Search on Vulmon Subscribe to Product

opensymphony xwork 2.2.1

apache struts 2.2.1

opensymphony xwork -

opensymphony webwork -