CVE-2013-1965
10.07.2013, 19:55
Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.
Vendor | Product | Version |
---|---|---|
apache | struts | 2.0.0 ≤ 𝑥 < 2.3.14.1 |
apache | struts2-showcase | 2.0.0 ≤ 𝑥 ≤ 2.3.13 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References