Vulnerability Name: | CVE-2008-6682 (CCN-50108) | ||||||||
Assigned: | 2008-01-11 | ||||||||
Published: | 2008-01-11 | ||||||||
Updated: | 2009-04-28 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-6682 Source: CCN Type: VMWare KB Article: 1034175 Workarounds for vCenter Orchestrator Address Apache Struts Remote Code Execution Vulnerability Source: CCN Type: SA43717 VMware vCenter Server Orchestrator Multiple Vulnerabilities Source: CCN Type: Apache Struts Web site Struts Source: CONFIRM Type: Patch http://www.nabble.com/Feedback%3A-WW-2414%2C-XSS-attack-is-possible-if-using-%3Cs%3Aurl-...%3E-and-%3Cs%3Aa-...%3E-td14771449.html Source: CONFIRM Type: Patch http://www.nabble.com/Feedback%3A-WW-2414%2C-XSS-attack-is-possible-if-using-%3Cs%3Aurl-...%3E-and-%3Cs%3Aa-...%3E-td14771449i20.html Source: CCN Type: OSVDB ID: 54122 Apache Struts s:a / s:url Tag href Element XSS Source: BID Type: UNKNOWN 34686 Source: CCN Type: BID-34686 Apache Struts Multiple Cross Site Scripting Vulnerabilities Source: CCN Type: MSA-2011-0005 VMware vCenter Server Orchestrator Multiple Vulnerabilities Source: XF Type: UNKNOWN struts-satag-surltag-xss(50108) Source: CCN Type: Apache Struts JIRA Bug WW-2414 Tags < s:url > and < s:a > do not encode URLs Source: CONFIRM Type: Vendor Advisory https://issues.apache.org/struts/browse/WW-2414 Source: CCN Type: Apache Struts JIRA Bug WW-2427 s:a does not HTML-escape "href" attribute value Source: CONFIRM Type: Vendor Advisory https://issues.apache.org/struts/browse/WW-2427 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |