Skip to content

CVE-2012-1007 @ Maven-org.apache.struts:struts-core-1.3.8 #94

@srcdev888

Description

@srcdev888

Vulnerable Package issue exists @ Maven-org.apache.struts:struts-core-1.3.8 in branch master

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookbook/processSimple.do or (3) struts-cookbook/processDyna.do.

Namespace: srcdevel1
Repository: dvja
Repository Url: https://github.com/srcdevel1/dvja
CxAST-Project: srcdevel1/dvja
CxAST platform scan: 275e3e87-21b4-460d-8d79-5eeebeb21604
Branch: master
Application: dvja
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-79


Addition Info


References
Other

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions