CVE-2005-3745

Apache Struts 1.2.7 - Cross-Site Scripting via Query String in Error Message

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-3745. PoCs published by Irene Abezgauz.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Struts, where user-supplied input is not properly sanitized. The example demonstrates how an attacker could inject arbitrary script code into a URL to execute in the context of the affected site.

Description

Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Irene Abezgauz · textremotemultiple
https://www.exploit-db.com/exploits/26542

The provided text describes a cross-site scripting (XSS) vulnerability in Struts, where user-supplied input is not properly sanitized. The example demonstrates how an attacker could inject arbitrary script code into a URL to execute in the context of the affected site.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Apache Struts (version not specified)
No auth needed
Prerequisites: A vulnerable version of Apache Struts · Ability to craft a malicious URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (13)

Core 13
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0161.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2525
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21021
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15512
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.hacktics.com/AdvStrutsNov05.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/417296/30/0/threaded
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2006-0157.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015257
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/197
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17677
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18341

Scores

EPSS 0.5907
EPSS Percentile 98.3%

Details

Status published
Products (2)
apache/struts 1.2.7
org.apache.struts/struts-core 0Maven
Published Nov 22, 2005
Tracked Since Feb 18, 2026