CVE-2008-6504
Opensymphony Xwork < 2.0.6 - Improper Input Validation
Title source: ruleDescription
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Meder Kydyraliev · textremotemultiple
https://www.exploit-db.com/exploits/32564
References (11)
Scores
EPSS
0.6512
EPSS Percentile
98.5%
Details
CWE
CWE-20
Status
published
Products (21)
apache/struts
2.0.0
apache/struts
2.0.2
apache/struts
2.0.3
apache/struts
2.0.4
apache/struts
2.0.5
apache/struts
2.0.6
apache/struts
2.0.7
apache/struts
2.0.8
apache/struts
2.0.9
apache/struts
2.0.11
... and 11 more
Published
Mar 23, 2009
Tracked Since
Feb 18, 2026