Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2010-1870 | First vendor Publication | 2010-08-17 |
| Vendor | Cve | Last vendor Modification | 2011-09-21 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:N) | |||
|---|---|---|---|
| Cvss Base Score | 5 | Attack Range | Network |
| Cvss Impact Score | 2.9 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6) #_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9) #_keepLastEvaluation, and possibly other OGNL context variables, a different vulnerability than CVE-2008-6504. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1870 |
CPE : Common Platform Enumeration
SAINT Exploits
| Description | Link |
|---|---|
| Apache Struts2 XWork ParameterInterceptor security bypass | More info here |
ExploitDB Exploits
| id | Description |
|---|---|
| 2010-07-14 | Struts2/XWork < 2.2.0 Remote Command Execution Vulnerability |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 66280 | Struts XWork ParameterInterceptor Server-Side Object Remote Code Execution |
Metasploit Database
| id | Description |
|---|---|
| 2010-07-13 | Apache Struts < 2.2.0 Remote Command Execution |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-06-11 17:25:13 |
|
| 2013-06-11 13:25:34 |
|
| 2013-06-10 13:25:29 |
|
| 2013-06-10 09:25:21 |
|
| 2013-06-08 05:26:40 |
|
| 2013-06-07 21:25:05 |
|
| 2013-06-06 13:25:57 |
|
| 2013-06-06 05:24:33 |
|
| 2013-06-04 17:26:04 |
|
| 2013-06-04 13:25:15 |
|
| 2013-06-03 21:27:41 |
|
| 2013-06-03 17:21:49 |
|
| 2013-06-03 13:26:05 |
|
| 2013-06-03 05:22:14 |
|
| 2013-05-31 21:26:01 |
|
| 2013-05-31 17:21:52 |
|
| 2013-05-30 17:24:47 |
|
| 2013-05-30 13:21:56 |
|
| 2013-05-10 23:25:08 |
|
| 2013-05-01 17:22:38 |
|
| 2013-05-01 13:28:06 |
|
| 2013-05-01 09:22:47 |
|
| 2013-05-01 05:38:31 |
|

CVE-2010-1870
(Medium)








