PT-2012-1242 · Apache · Apache Struts
Publicado
2012-02-01
·
Atualizado
2022-05-17
·
CVE-2012-1006
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Struts versions 2.0.14 through 2.2.3
Description
The issue allows remote attackers to inject arbitrary web script or HTML via the
name or lastName parameter to "struts2-showcase/person/editPerson.action", or the clientName parameter to "struts2-rest-showcase/orders". This is due to the lack of protection measures for the web page structure, enabling an attacker to conduct a cross-site scripting (XSS) attack using a specially crafted URL.Recommendations
For Apache Struts versions 2.0.14 through 2.2.3, consider disabling access to the
struts2-showcase/person/editPerson.action and struts2-rest-showcase/orders endpoints until a patch is available. Restrict the use of the name, lastName, and clientName parameters in these endpoints to minimize the risk of exploitation.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Struts