5.8
CVSSv2

CVE-2013-4310

Published: 30/09/2013 Updated: 05/05/2014
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Apache Struts 2.0.0 up to and including 2.3.15.1 allows remote malicious users to bypass access controls via a crafted action: prefix.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 2.3.15

apache struts 2.3.14.3

apache struts 2.3.1

apache struts 2.2.3.1

apache struts 2.1.4

apache struts 2.1.3

apache struts 2.0.6

apache struts 2.0.5

apache struts 2.0.11.2

apache struts 2.0.11.1

apache struts 2.3.4

apache struts 2.3.3

apache struts 2.3.1.2

apache struts 2.3.1.1

apache struts 2.1.6

apache struts 2.1.5

apache struts 2.0.8

apache struts 2.0.7

apache struts 2.0.13

apache struts 2.0.12

apache struts 2.3.8

apache struts 2.3.14.2

apache struts 2.3.14.1

apache struts 2.2.3

apache struts 2.2.1.1

apache struts 2.1.2

apache struts 2.1.1

apache struts 2.0.4

apache struts 2.0.3

apache struts 2.0.11

apache struts 2.0.10

apache struts 2.0.1

apache struts 2.3.7

apache struts 2.3.4.1

apache struts 2.3.14

apache struts 2.3.12

apache struts 2.2.1

apache struts 2.1.8.1

apache struts 2.1.8

apache struts 2.1.0

apache struts 2.0.9

apache struts 2.0.2

apache struts 2.0.14

apache struts 2.0.0

apache struts 2.3.15.1

Vendor Advisories

Apache Struts 200 through 23151 allows remote attackers to bypass access controls via a crafted action: prefix ...

Recent Articles

Apache Upgrade Repairs Struts, Fixes Two Vulnerabilities
Threatpost • Chris Brook • 23 Sep 2013

Developers behind the Apache Struts framework have released an update that fixes two vulnerabilities.
Creators of the open-source web application framework are encouraging users to upgrade to Struts 2.3.15.2 immediately.
One of the fixes addresses an issue (CVE-2013-4316) in the Dynamic Method Invocation (DMI) feature that was previously thought to break users’ applications if relied on too heavily. It was previously enabled by default and flashed a warning that users should switch...