CVE-2012-1007

Apache Struts 1.3.10 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.

Exploits (1)

exploitdb WORKING POC
by SecPod Research · textwebappsmultiple
https://www.exploit-db.com/exploits/18452

Scores

EPSS 0.2302
EPSS Percentile 95.9%

Details

CWE
CWE-79
Status published
Products (3)
apache/struts 1.3.10
org.apache.struts/struts-core 0Maven
struts/struts 0Maven
Published Feb 07, 2012
Tracked Since Feb 18, 2026