CVE-2005-3745
Apache Struts Cross-site scripting Vulnerability
EPSS 25.7%
描述
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly quoted or filtered when the request handler generates an error message.
如何修補 CVE-2005-3745
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
CVE-2005-3745 正在被利用嗎?
中等 — EPSS 為 25.7%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, <= 1.2.7