NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20086 | CVE-2016-4430 | Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-19 | 2016-10-06 | View | |
42906 | CVE-2012-0838 | Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field. | 2 | 10 | High | 2017-01-19 | 2013-07-26 | View | |
38091 | CVE-2013-1966 | Apache Struts 2 before 2.3.14.1 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. | 2 | 9.3 | High | 2017-01-18 | 2013-07-11 | View | |
38215 | CVE-2013-2115 | Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966. | 2 | 9.3 | High | 2017-01-18 | 2013-07-11 | View | |
38233 | CVE-2013-2134 | Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135. | 2 | 9.3 | High | 2017-01-18 | 2017-01-06 | View |
Page 1285 of 17672, showing 5 records out of 88360 total, starting on record 6421, ending on 6425