CVE-2008-6682

Apache Struts < 2.0.11.1 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.

Scores

EPSS 0.0143
EPSS Percentile 80.5%

Classification

CWE
CWE-79
Status published

Affected Products (7)

apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
org.apache.struts/struts2-core < 2.0.11.1Maven
n/a/n/a

Timeline

Published Apr 09, 2009
Tracked Since Feb 18, 2026