CVE-2012-1007
Apache Struts 1.3.10 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.
Exploits (1)
exploitdb
WORKING POC
by SecPod Research · textwebappsmultiple
https://www.exploit-db.com/exploits/18452
References (6)
Scores
EPSS
0.2302
EPSS Percentile
95.9%
Details
CWE
CWE-79
Status
published
Products (3)
apache/struts
1.3.10
org.apache.struts/struts-core
0Maven
struts/struts
0Maven
Published
Feb 07, 2012
Tracked Since
Feb 18, 2026