Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

László Tóth

Pesquisador dePricewaterhouseCoopers
#49136de 53,639
5CVSS total
Vulnerabilidades · 1
PT-2009-1975
5.0
2009-03-23
Apache · Apache Struts · CVE-2008-6505
**Name of the Vulnerable Software and Affected Versions** Apache Struts versions 2.0.x through 2.0.11 Apache Struts versions 2.1.x through 2.1.2 **Description** The issue allows remote attackers to read arbitrary files via a `..%252f` (encoded dot dot slash) in a URI with a "/struts/" path. This is related to the FilterDispatcher in 2.0.x and the DefaultStaticContentLoader in 2.1.x. **Recommendations** For Apache Struts versions 2.0.x through 2.0.11, update to version 2.0.12 or later. For Apache Struts versions 2.1.x through 2.1.2, update to version 2.1.3 or later. As a temporary workaround, consider restricting access to the `/struts/` path to minimize the risk of exploitation.