CVE-2011-1772

Apache Struts 2.x <2.2.3 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Dr. Marian Ventuneac · textremotemultiple
https://www.exploit-db.com/exploits/35735

References (10)

Core 10
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/1198
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/47784
Exploit, Patch x_refsource_confirm
http://struts.apache.org/2.x/docs/s2-006.html
Third Party Advisory third-party-advisory x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2011-000106
Third Party Advisory third-party-advisory x_refsource_jvn
http://jvn.jp/en/jp/JVN25435092/index.html

Scores

EPSS 0.5923
EPSS Percentile 98.3%

Details

CWE
CWE-79
Status published
Products (31)
apache/struts 2.0.0
apache/struts 2.0.1
apache/struts 2.0.2
apache/struts 2.0.3
apache/struts 2.0.4
apache/struts 2.0.5
apache/struts 2.0.6
apache/struts 2.0.7
apache/struts 2.0.8
apache/struts 2.0.9
... and 21 more
Published May 13, 2011
Tracked Since Feb 18, 2026