9.3
CVSSv2

CVE-2013-1965

Published: 10/07/2013 Updated: 12/08/2019
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Apache Struts Showcase App 2.0.0 up to and including 2.3.13, as used in Struts 2 prior to 2.3.14.3, allows remote malicious users to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts2-showcase

apache struts

Vendor Advisories

Apache Struts Showcase App 200 through 2313, as used in Struts 2 before 23141, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect ...
Check Point Reference: CPAI-2013-3910 Date Published: 13 Feb 2024 Severity: High ...

Github Repositories

A proof of concept exploit for the CVE-2013-1965 vulnerability affecting Apache Struts 2

CVE-2013-1965 A proof of concept exploit for the CVE-2013-1965 vulnerability affecting Apache Struts 2