ID:9820 - Exploit for Input validation error in Apache Struts - CVE-2013-2251

 
Main Vulnerability Database Exploits ID:9820 - Exploit for Input validation error in Apache Struts - CVE-2013-2251

ID:9820 - Exploit for Input validation error in Apache Struts - CVE-2013-2251

Published: May 21, 2024


Vulnerability identifier: #VU89696
Vulnerability risk: High
CVE-ID: CVE-2013-2251
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Apache Struts

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.


Remediation

Install updates from vendor's website.