CVE-2012-0838

EPSS 11.1%

Apache Struts Code injection due to conversion error

發布日:2022/5/14修改日:2024/12/5

描述

Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.

受影響套件(2)

參考連結(9)