CVE

Id
53637  
CVE No.
CVE-2012-0394  
Status
Candidate  
Description
** DISPUTED ** The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itself."  
Phase
Assigned (20120108)  
Votes
None (candidate not yet proposed)  
Comments