| Vulnerability Name: | CCN-77958 | ||||||
| Published: | 2012-08-22 | ||||||
| Updated: | 2012-08-22 | ||||||
| Summary: | Apache Struts could allow a remote attacker to execute arbitrary code on the system, caused by the improper validation of input. An attacker could exploit this vulnerability using the skill name method to execute arbitrary code on the system. | ||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
| CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:U/RC:UR)
| ||||||
| Vulnerability Consequences: | Gain Access | ||||||
| References: | Source: CCN Type: Packetstorm Security Website Apache Struts2 Remote Code Execution Source: CCN Type: Apache Struts Web site Struts Source: CCN Type: BID-55165 Apache Struts2 Skill Name Remote Code Execution Vulnerability Source: XF Type: UNKNOWN apache-struts-skillname-code-exec(77958) | ||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
| BACK | |||||||