570
VMScore

CVE-2016-1182

Published: 04/07/2016 Updated: 15/07/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 8.2 | Impact Score: 4.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

ActionServlet.java in Apache Struts 1 1.x up to and including 1.3.10 does not properly restrict the Validator configuration, which allows remote malicious users to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache struts 1.0

apache struts 1.1

apache struts 1.2.5

apache struts 1.2.6

apache struts 1.3.9

apache struts 1.3.10

apache struts 1.0.2

apache struts 1.2.1

apache struts 1.2.2

apache struts 1.2.9

apache struts 1.3.5

apache struts 1.2.3

apache struts 1.2.4

apache struts 1.3.7

apache struts 1.3.8

apache struts 1.3.6

apache struts 1.0.1

apache struts 1.2.0

apache struts 1.2.7

apache struts 1.2.8

Vendor Advisories

ActionServletjava in Apache Struts 1 1x through 1310 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899 ...

Github Repositories

Security patch for struts 1.3.8

struts-mini Security patch for struts 138 Struts 1 already stop official supporting for many years In these years, a few critical security vulnerabilities were found in struts 1 This project is a security patch for struts 138, below security vulnerabilities are solved: CVE-2016-1182 ActionServletjava in Apache Struts 1 1x through 1310 does not properly restrict the Va