PT-2009-2151 · Apache · Apache Struts

Publicado

2009-04-09

·

Atualizado

2022-05-17

·

CVE-2008-6682

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.0.x before 2.0.11.1 Apache Struts versions 2.1.x before 2.1.1
Description The issue is related to multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The improper handling of href attribute of an s:a tag, specifically with double quote characters, and parameters in the action attribute of an s:url tag are the causes of these vulnerabilities.
Recommendations For Apache Struts versions 2.0.x before 2.0.11.1, update to version 2.0.11.1 or later. For Apache Struts versions 2.1.x before 2.1.1, update to version 2.1.1 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6682
GHSA-JGCR-9C2Q-RVP8

Produtos afetados

Apache Struts