CVE-2013-2251
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1) action:, (2) redirect:, or (3) redirectAction: prefix.
- Affected products
- Apache Struts
- Apache Archiva
- < 1.3.8, 1.2, 1.2.2
- Apache Struts
- ≤ 2.3.15
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 100.0% (100th percentile)
- Weakness
- CWE-74
- NVD status
- Analyzed
- Published
- 2013-07-18
CVE-2013-2251 at NVD
19 known exploits for CVE-2013-2251
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2013-2251
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution
Apache Struts 2 Remote Code Execution
Apache Struts v3 - Tool To Exploit 3 RCE Vulnerabilities On ApacheStruts
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
Apache Struts2 2.0.0 2.3.15 - Prefixed Parameters OGNL Injection
Apache-Struts DefaultActionMapper < 2.3.15.1 RCE Linux
Struts2 2.3.15 OGNL Injection
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
Apache Struts DefaultActionMapper redirect Prefix Vulnerability
Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (Metasploit)
Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution
DSquare Exploit Pack: D2SEC_STRUTS4
Immunity Canvas: STRUTS2_DEFAULT_ACTION_MAPPER
Apache Struts2 多个前缀参数远程命令执行漏洞(CVE-2013-2251)
Apache Struts 2 DefaultActionMapper Prefixes OGNL Code Execution