CVE-2014-0112
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
- Affected products
- Apache Struts
- Apache Struts
- < 2.3.16.2
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 97.9% (100th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2014-04-29
CVE-2014-0112 at NVD
8 known exploits for CVE-2014-0112
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution Exploit
Apache Struts ClassLoader Manipulation Remote Code Execution
Struts2 远程命令执行
Apache Struts ClassLoader Manipulation Remote Code Execution Exploit
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
Apache Struts ClassLoader Manipulation Remote Code Execution
Apache Struts ClassLoader Manipulation Remote Code Execution
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)