NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
38234 | CVE-2013-2135 | Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice. | 2 | 9.3 | High | 2017-01-18 | 2014-05-05 | View | |
20090 | CVE-2016-4436 | Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up. | 2 | 7.5 | High | 2017-01-19 | 2016-10-21 | View | |
38338 | CVE-2013-2251 | Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix. | 2 | 9.3 | High | 2017-01-18 | 2016-12-07 | View | |
39935 | CVE-2013-4310 | Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix. | 2 | 5.8 | Medium | 2017-01-18 | 2014-05-05 | View | |
39941 | CVE-2013-4316 | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors. | 2 | 10 | High | 2017-01-18 | 2016-12-07 | View |
Page 1286 of 17672, showing 5 records out of 88360 total, starting on record 6426, ending on 6430