ID | CVE-2016-0785 | ||||||
Sažetak | Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. | ||||||
Reference | |||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:L/Au:S/C:C/I:C/A:C | ||||||
Zadnje važnije ažuriranje | 23-08-2019 - 15:50 | ||||||
Objavljeno | 12-04-2016 - 16:59 |