This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:apache:struts:2.0.2
Detail
VendorApacheFirst view 2010-08-17
ProductStrutsLast view 2012-09-05
Version2.0.2TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:apache:struts

Activity : Yearly

Related : CVE

 DateAlertAccess VectorAccess ComplexityAuthentification
52012-09-05CVE-2012-4387NetworkLowNone Requ...
6.82012-09-05CVE-2012-4386NetworkMediumNone Requ...
6.82012-01-08CVE-2012-0394NetworkMediumNone Requ...
6.42012-01-08CVE-2012-0393NetworkLowNone Requ...
9.32012-01-08CVE-2012-0392NetworkMediumNone Requ...
Hide | Show 5 More...
 DateAlertAccess VectorAccess ComplexityAuthentification
9.32012-01-08CVE-2012-0391NetworkMediumNone Requ...
52012-01-08CVE-2011-5057NetworkLowNone Requ...
4.32011-05-13CVE-2011-2087NetworkMediumNone Requ...
2.62011-05-13CVE-2011-1772NetworkHighNone Requ...
52010-08-17CVE-2010-1870NetworkLowNone Requ...

CWE : Common Weakness Enumeration

%idName
44% (4)CWE-264Permissions, Privileges, and Access Controls
22% (2)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
11% (1)CWE-352Cross-Site Request Forgery (CSRF)
11% (1)CWE-94Failure to Control Generation of Code ('Code Injection')
11% (1)CWE-20Improper Input Validation

Open Source Vulnerability Database (OSVDB)

idDescription
78277Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Exec...
78276Apache Struts DebuggingInterceptor Component Developer Mode Unspecified Remot...
78109Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite
78108Apache Struts CookieInterceptor Cookie Name Handling Remote Command Execution
77599Struts2 SessionAware / RequestAware Request Parsing Session Map Manipulation
Hide | Show 3 More...
idDescription
73600Apache Struts javatemplates Plugin Component Handlers .action URI Multiple Pa...
72238Apache Struts Action / Method Names Tag XWork Error Pages XSS
66280Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution

ExploitDB Exploits

idDescription
14360Struts2/XWork < 2.2.0 Remote Command Execution Vulnerability

Metasploit Exploits

idDescription
2012-01-06Apache Struts <= 2.2.1.1 Remote Command Execution
2010-07-13Apache Struts < 2.2.0 Remote Command Execution