CVE-2008-6504

Opensymphony Xwork < 2.0.6 - Improper Input Validation

Title source: rule

Description

ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Meder Kydyraliev · textremotemultiple
https://www.exploit-db.com/exploits/32564

Scores

EPSS 0.6512
EPSS Percentile 98.5%

Details

CWE
CWE-20
Status published
Products (21)
apache/struts 2.0.0
apache/struts 2.0.2
apache/struts 2.0.3
apache/struts 2.0.4
apache/struts 2.0.5
apache/struts 2.0.6
apache/struts 2.0.7
apache/struts 2.0.8
apache/struts 2.0.9
apache/struts 2.0.11
... and 11 more
Published Mar 23, 2009
Tracked Since Feb 18, 2026