CVE-2013-2134
EXPLOITEDApache Struts < 2.3.14.3 - Code Injection
Title source: ruleDescription
Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Jon Passki · textremotemultiple
https://www.exploit-db.com/exploits/38549
References (7)
Scores
EPSS
0.9153
EPSS Percentile
99.7%
Details
VulnCheck KEV
2025-10-13
CWE
CWE-94
Status
published
Products (3)
apache/struts
2.0.0 - 2.3.14.3
org.apache.struts/struts2-core
2.0.0 - 2.3.14.3Maven
org.apache.struts.xwork/xwork-core
2.0.0 - 2.3.14.3Maven
Published
Jul 16, 2013
Tracked Since
Feb 18, 2026