CVE-2014-0094

EXPLOITED

Apache Struts <2.3.16.2 - RCE

Title source: llm

Description

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

Exploits (4)

nomisec WRITEUP 1 stars
by y0d3n · poc
https://github.com/y0d3n/CVE-2014-0094
nomisec WORKING POC 1 stars
by HasegawaTadamitsu · poc
https://github.com/HasegawaTadamitsu/CVE-2014-0094-test-program-for-struts1
exploitdb WORKING POC
rubyremotemultiple
https://www.exploit-db.com/exploits/41690
exploitdb WORKING POC
rubyremotemultiple
https://www.exploit-db.com/exploits/33142

Scores

EPSS 0.9313
EPSS Percentile 99.8%

Details

VulnCheck KEV 2022-05-11
Status published
Products (3)
apache/struts 2.0.0 - 2.3.16.1
org.apache.struts/struts2-core 2.0.0 - 2.3.16.2Maven
org.apache.struts.xwork/xwork-core 2.0.0 - 2.3.16.2Maven
Published Mar 11, 2014
Tracked Since Feb 18, 2026