CVE-2014-0094
EXPLOITEDApache Struts <2.3.16.2 - RCE
Title source: llmDescription
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Exploits (4)
nomisec
WORKING POC
1 stars
by HasegawaTadamitsu · poc
https://github.com/HasegawaTadamitsu/CVE-2014-0094-test-program-for-struts1
References (15)
Scores
EPSS
0.9313
EPSS Percentile
99.8%
Details
VulnCheck KEV
2022-05-11
Status
published
Products (3)
apache/struts
2.0.0 - 2.3.16.1
org.apache.struts/struts2-core
2.0.0 - 2.3.16.2Maven
org.apache.struts.xwork/xwork-core
2.0.0 - 2.3.16.2Maven
Published
Mar 11, 2014
Tracked Since
Feb 18, 2026