CVE-2016-3081
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.
- Affected products
- Apache Struts
- Apache Struts
- = 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.11.1, 2.0.11.2, 2.0.12, 2.0.13, 2.0.14, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.8, 2.1.8.1, 2.2.1, 2.2.1.1, 2.2.3, 2.2.3.1, 2.3.1, 2.3.1.1, 2.3.1.2, 2.3.3, 2.3.4, 2.3.4.1, 2.3.7, 2.3.8, 2.3.12, 2.3.14
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 93.4% (100th percentile)
- Weakness
- CWE-77
- NVD status
- Modified
- Published
- 2016-04-26
CVE-2016-3081 at NVD
11 known exploits for CVE-2016-3081
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Struts Dynamic Method Invocation Expression Handling RCE
Apache Struts Dynamic Method Invocation command execution
Apache Struts Dynamic Method Invocation command execution
Apache Struts Dynamic Method Invocation command execution
Apache Struts Dynamic Method Invocation command execution
Apache Struts - Dynamic Method Invocation Remote Code Execution (Metasploit)
Apache Struts - Dynamic Method Invocation Remote Code Execution (Metasploit)
Apache Struts 2.3.28 Dynamic Method Invocation Remote Code Execution
Apache Struts Dynamic Method Invocation Remote Code Execution
Immunity Canvas: STRUTS2_DMI_RCE
Struts2 方法调用远程代码执行漏洞(S2-032)