CVE-2007-4556
NUCLEIOpenSymphony XWork <2.0.4 - DoS
Title source: llmDescription
Struts support in OpenSymphony XWork before 1.2.3, and 2.x before 2.0.4, as used in WebWork and Apache Struts, recursively evaluates all input as an Object-Graph Navigation Language (OGNL) expression when altSyntax is enabled, which allows remote attackers to cause a denial of service (infinite loop) or execute arbitrary code via form input beginning with a "%{" sequence and ending with a "}" character.
Nuclei Templates (1)
OpenSymphony XWork/Apache Struts2 - Remote Code Execution
MEDIUMby pikpikcu
References (14)
Scores
EPSS
0.0211
EPSS Percentile
84.2%
Details
Status
published
Products (2)
opensymphony/xwork
< 1.2.3
opensymphony/xwork
0 - 1.2.3Maven
Published
Aug 28, 2007
Tracked Since
Feb 18, 2026