CVE-2016-4461
16.10.2017, 16:29
Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.Enginsight
Vendor | Product | Version |
---|---|---|
apache | struts | 2.0.0 ≤ 𝑥 < 2.3.29 |
netapp | oncommand_balance | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration