JVN#25435092Third-party advisory
http://jvn.jp/en/jp/JVN25435092/index.html CVE-2011-1772
Cross-site Scripting in Apache Struts
Record summary
CVE-2011-1772 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.apache.struts:struts2-coreBrowse Maven / org.apache.struts:struts2-core | GitHub Advisory | Before 2.2.3 · Fixed in 2.2.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBApache Struts 2.0.0 < 2.2.1.1 - XWork 's:submit' HTML Tag Cross-Site ScriptingExploitDB exploitby Dr. Marian VentuneacNot analyzed1 file
References
12JVNDB-2011-000106Third-party advisory
http://jvndb.jvn.jp/jvndb/JVNDB-2011-000106 secureappdev.blogspot.com
http://secureappdev.blogspot.com/2011/05/Struts_2_XWork_WebWork_XSS_in_error_pages.html secureappdev.blogspot.com
http://secureappdev.blogspot.com/2011/05/apache-struts-2-xwork-webwork-reflected.html struts.apache.orgConfirmation
http://struts.apache.org/2.2.3/docs/version-notes-223.html struts.apache.orgConfirmation
http://struts.apache.org/2.x/docs/s2-006.html 47784vdb entry
http://www.securityfocus.com/bid/47784 ventuneac.net
http://www.ventuneac.net/security-advisories/MVSA-11-006 ADV-2011-1198vdb entry
http://www.vupen.com/english/advisories/2011/1198 github.com
https://github.com/apache/struts issues.apache.orgConfirmation
https://issues.apache.org/jira/browse/WW-3579 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-1772