PT-2012-1242 · Apache · Apache Struts

Publicado

2012-02-01

·

Atualizado

2022-05-17

·

CVE-2012-1006

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Struts versions 2.0.14 through 2.2.3
Description The issue allows remote attackers to inject arbitrary web script or HTML via the name or lastName parameter to "struts2-showcase/person/editPerson.action", or the clientName parameter to "struts2-rest-showcase/orders". This is due to the lack of protection measures for the web page structure, enabling an attacker to conduct a cross-site scripting (XSS) attack using a specially crafted URL.
Recommendations For Apache Struts versions 2.0.14 through 2.2.3, consider disabling access to the struts2-showcase/person/editPerson.action and struts2-rest-showcase/orders endpoints until a patch is available. Restrict the use of the name, lastName, and clientName parameters in these endpoints to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-06340
CVE-2012-1006
GHSA-CMPM-JG8R-FV37

Produtos afetados

Apache Struts