Executive Summary

Informations
NameCVE-2012-0393First vendor Publication2012-01-08
VendorCveLast vendor Modification2012-01-12

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:P)
Cvss Base Score6.4Attack RangeNetwork
Cvss Impact Score4.9Attack ComplexityLow
Cvss Expoit Score10AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0393

CWE : Common Weakness Enumeration

idName
CWE-264Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application30

Open Source Vulnerability Database (OSVDB)

idDescription
78109Apache Struts ParameterInterceptor Traversal Arbitrary File Overwrite

Internal Sources (Detail)

SourceUrl
BUGTRAQhttp://archives.neohapsis.com/archives/bugtraq/2012-01/0031.html
CONFIRMhttp://struts.apache.org/2.x/docs/s2-008.html
http://struts.apache.org/2.x/docs/version-notes-2311.html
EXPLOIT-DBhttp://www.exploit-db.com/exploits/18329
MISChttps://www.sec-consult.com/files/20120104-0_Apache_Struts2_Multiple_Critical...
SECUNIAhttp://secunia.com/advisories/47393

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2013-05-10 22:32:21
  • Multiple Updates