Executive Summary
| Informations | |||
|---|---|---|---|
| Name | CVE-2012-0391 | First vendor Publication | 2012-01-08 |
| Vendor | Cve | Last vendor Modification | 2012-01-10 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 9.3 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Medium |
| Cvss Expoit Score | 8.6 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a crafted parameter. |
Original Source
| Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0391 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-20 | Improper Input Validation |
CPE : Common Platform Enumeration
SAINT Exploits
| Description | Link |
|---|---|
| Apache Struts 2 ConversionErrorInterceptor Java Injection | More info here |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 78277 | Apache Struts ExceptionDelegator Component Parameter Parsing Remote Code Exec... |
Metasploit Database
| id | Description |
|---|---|
| 2012-01-06 | Apache Struts <= 2.2.1.1 Remote Command Execution |
Internal Sources (Detail)
Alert History
| Date | Informations |
|---|---|
| 2013-05-10 22:32:21 |
|

CVE-2012-0391
(Critical)







