CVE-2008-6682
Apache Struts < 2.0.11.1 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.
References (5)
Scores
EPSS
0.0143
EPSS Percentile
80.5%
Classification
CWE
CWE-79
Status
published
Affected Products (7)
apache/struts
apache/struts
apache/struts
apache/struts
apache/struts
org.apache.struts/struts2-core
< 2.0.11.1Maven
n/a/n/a
Timeline
Published
Apr 09, 2009
Tracked Since
Feb 18, 2026