Record summary

CVE-2011-1772 has a selected CVSS score of 2.6; EIP currently links 1 catalogued exploit.

Description

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the action attribute of an s:submit element, or (3) the method attribute of an s:submit element.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

org.apache.struts:struts2-core

Browse Maven / org.apache.struts:struts2-core
GitHub AdvisoryBefore 2.2.3 · Fixed in 2.2.3affected

Proofs of concept

1

Catalogued exploits

ExploitDBApache Struts 2.0.0 < 2.2.1.1 - XWork 's:submit' HTML Tag Cross-Site ScriptingExploitDB exploitby Dr. Marian VentuneacNot analyzed1 file
ExploitDB

PoC details

References

12