Description
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Dr. Marian Ventuneac · textremotemultiple
https://www.exploit-db.com/exploits/35735
References (10)
Core 10
Core References
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/1198
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/47784
Exploit, Patch x_refsource_confirm
http://struts.apache.org/2.x/docs/s2-006.html
Third Party Advisory third-party-advisory
x_refsource_jvndb
http://jvndb.jvn.jp/jvndb/JVNDB-2011-000106
Third Party Advisory third-party-advisory
x_refsource_jvn
http://jvn.jp/en/jp/JVN25435092/index.html
Various Sources x_refsource_misc
http://secureappdev.blogspot.com/2011/05/Struts_2_XWork_WebWork_XSS_in_error_pages.html
Various Sources x_refsource_confirm
http://struts.apache.org/2.2.3/docs/version-notes-223.html
Exploit x_refsource_misc
http://www.ventuneac.net/security-advisories/MVSA-11-006
Patch x_refsource_confirm
https://issues.apache.org/jira/browse/WW-3579
Exploit x_refsource_misc
http://secureappdev.blogspot.com/2011/05/apache-struts-2-xwork-webwork-reflected.html
Scores
EPSS
0.5923
EPSS Percentile
98.3%
Details
CWE
CWE-79
Status
published
Products (31)
apache/struts
2.0.0
apache/struts
2.0.1
apache/struts
2.0.2
apache/struts
2.0.3
apache/struts
2.0.4
apache/struts
2.0.5
apache/struts
2.0.6
apache/struts
2.0.7
apache/struts
2.0.8
apache/struts
2.0.9
... and 21 more
Published
May 13, 2011
Tracked Since
Feb 18, 2026