漏洞类别:Web Application
漏洞等级:
漏洞信息
The Apache Struts web framework is a free open source solution for creating Java web applications.
A vulnerability CVE-2013-1966 and CVE-2013-2115 exists due to Invalid handling of "includeParams" attribute, which leads to code execution by forcing parameter inclusion in the URL and Anchor Tag.
Affected Software:
Apache Struts versions 2.0.0 through 2.3.14.1 are vulnerable.
漏洞危害
If successful, an attacker can manipulate server-side context objects with the privileges of the user running the application and execute arbitrary code.
解决方案
0day
文章评论