Search Results (Refine Search)
- CPE Product Version: cpe:/a:apache:struts:1.0:beta3
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2016-1182 |
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899. Published: July 04, 2016; 6:59:02 PM -0400 |
V3.0: 8.2 HIGH V2.0: 6.4 MEDIUM |
CVE-2016-1181 |
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899. Published: July 04, 2016; 6:59:01 PM -0400 |
V3.0: 8.1 HIGH V2.0: 6.8 MEDIUM |