CVE-2014-0094
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
- Affected products
- Apache Struts
- Apache Struts
- < 2.3.16.1
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 99.6% (100th percentile)
- NVD status
- Modified
- Published
- 2014-03-10
CVE-2014-0094 at NVD
9 known exploits for CVE-2014-0094
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution Exploit
Apache Struts ClassLoader Manipulation Remote Code Execution
Struts2 远程命令执行
Apache Struts ClassLoader Manipulation Remote Code Execution Exploit
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
Apache Struts ClassLoader Manipulation Remote Code Execution
Apache Struts ClassLoader Manipulation Remote Code Execution
Apache Struts ClassLoader操作漏洞
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)